Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, the /ffprobe endpoint accepts arbitrary user-controlled URLs without proper validation, allowing Server-Side Request Forgery (SSRF) attacks. An attacker can use the Frigate server to make HTTP requests to internal network resources, cloud metadata services, or perform port scanning. This issue has been patched in version 0.16.3.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frigate
Frigate frigate |
|
| CPEs | cpe:2.3:a:frigate:frigate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frigate
Frigate frigate |
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blakeblackshear
Blakeblackshear frigate |
|
| Vendors & Products |
Blakeblackshear
Blakeblackshear frigate |
Fri, 20 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, the /ffprobe endpoint accepts arbitrary user-controlled URLs without proper validation, allowing Server-Side Request Forgery (SSRF) attacks. An attacker can use the Frigate server to make HTTP requests to internal network resources, cloud metadata services, or perform port scanning. This issue has been patched in version 0.16.3. | |
| Title | Frigate has SSRF vulnerability in /ffprobe endpoint | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-20T19:57:16.438Z
Reserved: 2026-03-17T20:35:49.926Z
Link: CVE-2026-33126
No data.
Status : Analyzed
Published: 2026-03-20T20:16:48.597
Modified: 2026-03-23T19:17:05.200
Link: CVE-2026-33126
No data.
OpenCVE Enrichment
Updated: 2026-03-23T09:52:55Z
Weaknesses