Vulnerability GHSA-87mg-5grr-rhwh

Low Risk
LOW RISK
CVSS Score: 3.1
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 days ago
September 24, 2026 at 07:59 PM UTC
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8

Summary

Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module

Details

Summary

The Feed Reader front-end module passes RSS feed URLs from its configuration directly to $this->feedIo->read($url) without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loopback addresses, causing the server to fetch those resources unconditionally. Confirmed live: the server successfully reaches the internal MySQL database container and its own loopback Apache instance.

Impact

This is a CWE-918 (SSRF) vulnerability. A backend user with module-edit access can:

  1. Enumerate internal network services -- probe any IP/port on the internal network by observing response times and error messages
  2. Reach internal APIs -- access unauthenticated services inside the Docker/Kubernetes network (databases, caches, admin panels)
  3. Steal cloud metadata credentials -- on AWS, fetch http://169.254.169.254/latest/meta-data/iam/security-credentials/ to obtain IAM role credentials (IMDSv1 has no authentication)
  4. Pivot to internal infrastructure -- use the server as a proxy to interact with services not exposed to the public internet

Confirmed in live testing: the server successfully connected to the internal MySQL container (172.19.0.3:3306) and retrieved a full HTTP response from its own loopback interface (127.0.0.1:80).

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao crawler leaks auth credentials to external hosts
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
Low Risk
1 month ago
Contao crawler leaks auth credentials to external hosts
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
Low Risk
10 months ago
Contao is vulnerable to cross-site scripting in templates
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-68q5-78xp-cwwc
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-68q5-78xp-cwwc
View all vulnerabilities for these packages

Timeline

Published
3 days ago
September 24, 2026 at 07:59 PM UTC
Fixed (5.3.48)
2 months ago
July 13, 2026 at 08:41 AM UTC
Fixed (5.3.48)
2 months ago
July 13, 2026 at 09:10 AM UTC
Fixed (5.7.9)
2 months ago
July 13, 2026 at 09:41 AM UTC
Fixed (5.7.9)
2 months ago
July 13, 2026 at 09:41 AM UTC
Last Modified
3 days ago
September 24, 2026 at 08:15 PM UTC