PT-2026-102893 · Fider · Fider

·

CVE-2026-102877

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fider versions prior to 0.38.0
Description A server-side request forgery issue exists due to a time-of-check time-of-use (TOCTOU) gap—a race condition where a system checks a condition and then uses the result, but the condition changes between the check and the use—during URL validation for webhooks and custom OAuth provider endpoints. This allows administrators with DNS control to execute DNS rebinding attacks, forcing the server to send unauthorized requests to internal services or cloud metadata endpoints.
Recommendations Update Fider to version 0.38.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102877
GHSA-WHX4-HXWQ-QGJH

Affected Products

Fider