CVE-2026-19913
Kaltura Kaltura HTML5 Video Player, html5lib library
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the client in an error message; this enables an unauthenticated, remote attacker to read any arbitrary internal file reachable by the server. Affected versions include html5lib v2.45, v2.103 and earlier, a...
- CVSS
- 7.5
- EPSS
- 0.36% 28.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.26