Server-Side Request Forgery in Fider Due to Validation Flaws
CVE-2026-102877
2.1LOW
What is CVE-2026-102877?
Fider versions before 0.38.0 are vulnerable to a server-side request forgery due to a gap in the validation process for webhooks and custom OAuth provider endpoints. This vulnerability allows attackers with control over DNS settings to exploit DNS rebinding attacks, enabling them to manipulate the Fider server into making unauthorized requests to internal services or cloud metadata endpoints. It is crucial for administrators to update to version 0.38.0 or later to mitigate this risk.
Affected Version(s)
fider 0 < 0.38.0
fider 0.38.0
