CVE-2026-6220 | HummerRisk up to 1.5.0 Video File Download URL ServerService.java ServerService.addServer streamIp server-side request forgery
A vulnerability classified as critical was found in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServer of the file ServerService.java of the component Video File Download URL Handler. Such manipulation of the argument streamIp leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-6220. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.