---
id: CVE-2026-102877
title: >-
  Fider before 0.38.0 contains a server-side request forgery vulnerability due
  to a time-of-check time-of-use gap in URL validation for webhooks and custom
  OAuth provider endpoints
summary: >-
  Fider before 0.38.0 contains a server-side request forgery vulnerability due
  to a time-of-check time-of-use gap in URL validation for webhooks and custom
  OAuth provider endpoints. Administrators controlling DNS can perform DNS
  rebinding …
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: getfider
product: fider
affected:
  - fider < 0.38.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:17:18.433'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102877'
references:
  - url: 'https://github.com/getfider/fider'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getfider/fider/blob/v0.37.0/app/pkg/validate/general.go'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/getfider/fider/blob/v0.37.0/app/services/httpclient/httpclient.go
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/getfider/fider/commit/45f5627b9fd15b912fb9092635c863fb4c91dd69
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getfider/fider/releases/tag/v0.38.0'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getfider/fider/security/advisories/GHSA-whx4-hxwq-qgjh'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/fider-before-0.38.0-ssrf-via-dns-rebinding-in-webhook-validation
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T20:46:06.443Z'
---

## Overview

Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
