CVE-2026-100901
Published 28 September 2026 · tracked since 28 September 2026
Description
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-91206 MEDIUM 6.1
- CVE-2026-82382 MEDIUM 6.1
- CVE-2026-82383 HIGH 8.2
- CVE-2026-82384 CRITICAL 9.8
- CVE-2026-82385 MEDIUM 6.5
- CVE-2026-82386 HIGH 7.7
- CVE-2026-82387 MEDIUM 5.4
- CVE-2026-82546 MEDIUM 6.1
- CVE-2026-91204 MEDIUM 6.1
- CVE-2026-82375 HIGH 7.4