Skip to content

fix(activitypub): validate nodeinfo redirect host and scheme before fetching - #111

Open
prasanna8585 wants to merge 1 commit into
NextDotID:developfrom
prasanna8585:fix/activitypub-ssrf-host-validation
Open

prasanna8585 wants to merge 1 commit into
NextDotID:developfrom
prasanna8585:fix/activitypub-ssrf-host-validation

Conversation

@prasanna8585

Copy link
Copy Markdown

Summary

DetectServerSoftware() performs a second HTTP request to a URL (link.Href) taken directly from the JSON response of the first, attacker-controlled request, with no validation that the target:

  • belongs to the same host as the original identity's server, or
  • uses https.

This allows an attacker who controls the identity's domain to redirect the second request to an internal/private address (SSRF), enabling network reconnaissance or use as a pivot in combination with other vulnerabilities.

Fix

Validate that link.Href's scheme is https and its hostname matches the originally-requested serverURL before fetching it.

Reachability note

Confirmed reachable via POST /v1/proof (not /v1/proof/payload as initially reported).

…etching

DetectServerSoftware() performed a second HTTP request to a URL
(link.Href) taken directly from the JSON response of the first,
attacker-controlled request, with no validation that the target
belonged to the same host as the original identity's server or used
https. This allowed SSRF via a crafted nodeinfo response redirecting
to an internal/private address.

Validates that link.Href's scheme is https and its hostname matches
the originally-requested serverURL before fetching it.

Confirmed reachable via POST /v1/proof.
@prasanna8585
prasanna8585 force-pushed the fix/activitypub-ssrf-host-validation branch from 226db91 to 4826b57 Compare September 24, 2026 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant