A05: add SSRF guards to webhook delivery #14

Closed
opened 2026-08-13 09:35:03 +00:00 by nalum · 0 comments
Owner

validateTargetURL (internal/services/webhook/create.go:77-93) accepts any http/https URL with a host. The sender (internal/webhook/sender.go:31-35) uses http.DefaultClient, which follows up to 10 redirects, and there is no private-range, loopback, or link-local blocking and no re-resolution guard. An admin-configured hook can probe cluster-internal services (kube API, zot, CNPG, ntfy admin routes) and read status codes and latency as an oracle.

Mitigations today: creation is admin-gated, the request is a POST with a fixed JSON body, and LAN targets are the product's point. ADR-0024 records the deferral. This must land before webhook management ever widens beyond admins.

Fix

  • Block loopback, link-local, and RFC1918 targets unless explicitly allowed.
  • Disable redirect following (or re-validate each hop).
  • Pin the resolved IP for the request to prevent DNS rebinding.

Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`validateTargetURL` (`internal/services/webhook/create.go:77-93`) accepts any http/https URL with a host. The sender (`internal/webhook/sender.go:31-35`) uses `http.DefaultClient`, which follows up to 10 redirects, and there is no private-range, loopback, or link-local blocking and no re-resolution guard. An admin-configured hook can probe cluster-internal services (kube API, zot, CNPG, ntfy admin routes) and read status codes and latency as an oracle. Mitigations today: creation is admin-gated, the request is a POST with a fixed JSON body, and LAN targets are the product's point. ADR-0024 records the deferral. This must land before webhook management ever widens beyond admins. **Fix** - Block loopback, link-local, and RFC1918 targets unless explicitly allowed. - Disable redirect following (or re-validate each hop). - Pin the resolved IP for the request to prevent DNS rebinding. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:47 +00:00
nalum closed this issue 2026-08-13 11:39:45 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#14
No description provided.