A05: add SSRF guards to webhook delivery #14
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#14
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
validateTargetURL(internal/services/webhook/create.go:77-93) accepts any http/https URL with a host. The sender (internal/webhook/sender.go:31-35) useshttp.DefaultClient, which follows up to 10 redirects, and there is no private-range, loopback, or link-local blocking and no re-resolution guard. An admin-configured hook can probe cluster-internal services (kube API, zot, CNPG, ntfy admin routes) and read status codes and latency as an oracle.Mitigations today: creation is admin-gated, the request is a POST with a fixed JSON body, and LAN targets are the product's point. ADR-0024 records the deferral. This must land before webhook management ever widens beyond admins.
Fix
Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.