CVE-2026-82645: Avideo Insecure Decrypt String Intval
Directly converting decrypted token strings to integers using intval() without validating that the plaintext strictly contains digits allows forged or spliced CBC ciphertexts to bypass authentication/authorization checks.
greprules fetch cve-2026-82645-avideo-insecure-decrypt-string-intval --engine opengrepDescription
Directly converting decrypted token strings to integers using intval() without validating that the plaintext strictly contains digits allows forged or spliced CBC ciphertexts to bypass authentication/authorization checks.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.