Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Jan 16, 2025 
          in
          
            matrix-org/gomatrixserverlib
          
          •
          Updated Jan 17, 2025 
      
  
Package
Affected versions
<= 0.0.0-20250106190028-bf86bc98b879
  Patched versions
0.0.0-20250116181547-c4f1e01eab0d
  Description
        Published by the National Vulnerability Database
      Jan 16, 2025 
    
  
        Published to the GitHub Advisory Database
      Jan 16, 2025 
    
  
        Reviewed
      Jan 16, 2025 
    
  
        Last updated
      Jan 17, 2025 
    
  
Impact
Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions.
Patches
c4f1e01eab0dd435709ad15463ed38a079ad6128 fixes this issue.
Workarounds
Use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
References
N/A
References