CVE-2026-56285
Severity CVSS v4.0:
HIGH
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
29/06/2026
Last modified:
14/07/2026
Description
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
8.60
Severity 3.x
HIGH



