Server-Side Request Forgery in Fider Due to Validation Flaws
CVE-2026-102877

2.1LOW

Key Information:

Vendor

Getfider

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102877?

Fider versions before 0.38.0 are vulnerable to a server-side request forgery due to a gap in the validation process for webhooks and custom OAuth provider endpoints. This vulnerability allows attackers with control over DNS settings to exploit DNS rebinding attacks, enabling them to manipulate the Fider server into making unauthorized requests to internal services or cloud metadata endpoints. It is crucial for administrators to update to version 0.38.0 or later to mitigate this risk.

Affected Version(s)

fider 0 < 0.38.0

fider 0.38.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.