PT-2026-102893 · Fider · Fider
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fider versions prior to 0.38.0
Description
A server-side request forgery issue exists due to a time-of-check time-of-use (TOCTOU) gap—a race condition where a system checks a condition and then uses the result, but the condition changes between the check and the use—during URL validation for webhooks and custom OAuth provider endpoints. This allows administrators with DNS control to execute DNS rebinding attacks, forcing the server to send unauthorized requests to internal services or cloud metadata endpoints.
Recommendations
Update Fider to version 0.38.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fider