Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-87mg-5grr-rhwh
Summary
The Feed Reader front-end module passes RSS feed URLs from its configuration directly to $this->feedIo->read($url) without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loopback addresses, causing the server to fetch those resources unconditionally. Confirmed live: the server successfully reaches the internal MySQL database container and its own loopback Apache instance.
Details
In core-bundle/src/Controller/FrontendModule/FeedReaderController.php, the getResponse() function iterates over the configured feed URLs and passes each one directly to the HTTP client with no validation:
// Line 50-55
foreach (StringUtil::trimsplit('[\n\t ]', trim($model->rss_feed)) as $url) {
try {
$feed = $this->cache->get(
'feed_reader_'.$model->id.'_'.md5($url),
function (ItemInterface $item) use ($url, $model) {
$readerResult = $this->feedIo->read($url, new Feed()); // <-- no validation
The DCA field definition for rss_feed in tl_module.php carries no URL scheme or host validation:
'eval' => array('mandatory'=>true, 'decodeEntities'=>true, 'style'=>'height:60px')
The HTTP client is wired as @psr18.http_client (Symfony HttpClient) with no SSRF protection configured (NoPrivateNetworkHttpClient is not used).
Impact
This is a CWE-918 (SSRF) vulnerability. A backend user with module-edit access can:
- Enumerate internal network services -- probe any IP/port on the internal network by observing response times and error messages
- Reach internal APIs -- access unauthenticated services inside the Docker/Kubernetes network (databases, caches, admin panels)
- Steal cloud metadata credentials -- on AWS, fetch
http://169.254.169.254/latest/meta-data/iam/security-credentials/to obtain IAM role credentials (IMDSv1 has no authentication) - Pivot to internal infrastructure -- use the server as a proxy to interact with services not exposed to the public internet
Confirmed in live testing: the server successfully connected to the internal MySQL container (172.19.0.3:3306) and retrieved a full HTTP response from its own loopback interface (127.0.0.1:80).
Remediation
-
Use
NoPrivateNetworkHttpClient-- wrap the injected HTTP client with Symfony's built-in SSRF protection before passing it to feedIo:use Symfony\Component\HttpClient\NoPrivateNetworkHttpClient; $safeClient = new NoPrivateNetworkHttpClient($this->httpClient);This blocks all RFC-1918, loopback, and link-local addresses at the HTTP client level.
-
Validate URL scheme and host -- before calling
feedIo->read(), parse the URL and reject anything that is nothttp://orhttps://with a public routable IP or hostname. -
Configure the DCA field -- add
'rgxp' => 'url'and a custom validation callback totl_module.rss_feedto reject non-public URLs at save time.
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is difficult for an attacker to exploit this vulnerability and may require special conditions. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a low impact on the confidentiality of the information.
Limited exploitation activity has been observed. Close monitoring and planned remediation are recommended.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard