Fider before 0.38.0 contains a server-side request...
Low severity
Unreviewed
Published
Sep 29, 2026
to the GitHub Advisory Database
•
Updated Sep 29, 2026
Description
Published by the National Vulnerability Database
Sep 29, 2026
Published to the GitHub Advisory Database
Sep 29, 2026
Last updated
Sep 29, 2026
Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.
References