CVE-2026-102877
2.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Summary
Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getfider | fider | 0 < 0.38.0 | affected |
| getfider | fider | 0.38.0 | unaffected |
Weaknesses
- CWE-918: Server-Side Request Forgery (SSRF)
References
- https://github.com/getfider/fider/security/advisories/GHSA-whx4-hxwq-qgjh
- https://github.com/getfider/fider/commit/45f5627b9fd15b912fb9092635c863fb4c91dd69
- https://github.com/getfider/fider/blob/v0.37.0/app/pkg/validate/general.go
- https://github.com/getfider/fider/blob/v0.37.0/app/services/httpclient/httpclient.go
- https://github.com/getfider/fider/releases/tag/v0.38.0
- https://github.com/getfider/fider
- https://www.vulncheck.com/advisories/fider-before-0.38.0-ssrf-via-dns-rebinding-in-webhook-validation
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.