Server-side request forgery (SSRF) In github.com/matrix-org/gomatrixserverlib
Description
Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation
Impact
Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions.
Patches
c4f1e01eab0dd435709ad15463ed38a079ad6128 fixes this issue.
Workarounds
Use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
References
N/A
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.0.0-20250116181547-c4f1e01eab0d |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.