CVE-2026-33690: AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()
The getRealIpAddr() function in objects/functions.php trusts user-controlled HTTP headers to determine the client’s IP address.
An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access controls or audit logging.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33690 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →