CVE-2025-32948

PeerTube ActivityPub Playlist Creation Blind SSRF and DoS

The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.


We have discovered 155 live websites that are affected by CVE-2025-32948.

Run a Free Instant Scan




Affected Software

Product  PeerTube
Category Message Boards
Vulnerable Domains155 live websites (32% of PeerTube install base)
Vulnerable Versions
  • from 0 through 7.1.1
Vulnerable Versions Count23 versions ( 70% of all versions)


Common Weakness Enumeration

CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')



Details

  • Published - Apr 15, 2025
  • Updated - Apr 15, 2025

Website Distribution by Country

Number of websites using CVE-2025-32948
United States19 websites



France51 websites
Germany39 websites
Russia8 websites
Czech Republic5 websites
Belgium3 websites
Switzerland3 websites
Spain3 websites
GB3 websites
Poland3 websites

Website Distribution by TLD

Number of websites using CVE-2025-32948
.org23 websites
.com21 websites
.net13 websites
.fr13 websites
.de11 websites
.es5 websites
.pl4 websites
.eu4 websites
.be3 websites
.ru3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-32948

Top websites that are affected by CVE-2025-32948. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.zone United States***,***
****.tube France***,***
*****.*****.fr France***,***
********.br Brazil***,***
*****.tube France*,***,***
*****.*****.it Italy*,***,***
*****.*******.org Germany*,***,***
********.**********.online United States*,***,***
******.*************.fr European Union*,***,***
******.****.org France*,***,***
See full domain list

FAQ

CVE-2025-32948 is Access of Resource Using Incompatible Type ('Type Confusion') in PeerTube
A total of 155 websites have been identified as vulnerable to CVE-2025-32948, based on global website indexing conducted by WebTechSurvey.
The PeerTube is affected by the CVE-2025-32948 vulnerability.
PeerTube versions up to 7.1.1 are vulnerable to CVE-2025-32948.
CVE-2025-32948 is resolved in version 7.1.1 of PeerTube.