GSSA-2026-05-A5DE8WGITLAB-GSSA-2026-05-A5DE8WMay 4, 20266.4 Medium
SSRF in outbound project webhook delivery
A project admin could register an outbound webhook URL that resolved to internal addresses (cloud metadata, loopback, RFC1918), and the response body was persisted and exposed in the project settings UI. Fixed by validating URLs against a private-address blocklist before each delivery.
Affected (1)
- gelhaus-solutionscontributer-checker
- ≥ 0.0.0Fixed in 0.0.1
Mitigations
Workarounds
- Restrict project ADMIN role assignment to fully trusted operators until 0.0.1 is deployed.
- Block egress from the application host to cloud metadata IPs (169.254.169.254, fd00:ec2::254) and RFC1918 ranges at the firewall.
- On AWS, require IMDSv2 (HttpTokens=required) so the SSRF primitive cannot retrieve credentials with a single GET.
Solutions
- Upgrade to 0.0.1: outbound webhook URLs are validated by assertSafeOutboundUrl before every delivery (rejects loopback, link-local, private, CGNAT, multicast, and reserved ranges, plus localhost), DNS-resolved at delivery time, fetched with redirect:manual, and stored response bodies are capped at 256 bytes.
Exploits
- 1. Sign in as a project ADMIN. 2. Settings → Webhooks → Add → URL=http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>. 3. Trigger any project event (or use the test-send button). 4. Read the AWS STS credentials from the delivery row in the settings UI.
Configurations
- Self-hosted deployments where the application host has IP-level reachability to cloud metadata services (AWS/GCP/Azure) or to internal RFC1918 networks.
- Any deployment where project ADMIN is granted to non-host-administrators.
Overview
A project admin could register an outbound webhook URL pointing at internal addresses; the bot would fetch it and store the response body. Fixed in 0.0.1.
Severity
CVSS v4
6.4 Medium
6.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- High
- User interaction
- None
- Confidentiality (vulnerable system)
- None
- Integrity (vulnerable system)
- None
- Availability (vulnerable system)
- None
- Confidentiality (subsequent system)
- High
- Integrity (subsequent system)
- Low
- Availability (subsequent system)
- None
CVSS v3
7.6 High
7.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- High
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- Low
- Availability
- None
Weaknesses (1)
References (4)
- CWE-918: Server-Side Request Forgery (SSRF) (Technical description)
- OWASP — SSRF (Technical description)
- AWS — Configure IMDSv2 (Mitigation)
- OWASP WSTG — Testing for SSRF (Technical description)
Credits (2)
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausFinder · egelhaus@ennogelhaus.de
Context
Impacts
Exfiltration of cloud instance metadata credentials (e.g. AWS STS tokens) reachable from the application host.
CAPEC-664Internal network reconnaissance: a project ADMIN can probe arbitrary internal HTTP services and read up to 256 bytes of the response.