天下漏洞,尽知其名
MEDIUM

CVE-2026-102877 Fider 服务端请求伪造漏洞

原始情报

Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.