Loading market data...
← Back to CVE feed

CVE-2026-102877

MEDIUM CVSS 4.4 View on NVD ↗

Description

Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Published: Sep 29, 2026 20:17 UTC Modified: Sep 29, 2026 20:17 UTC