Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions.
c4f1e01eab0dd435709ad15463ed38a079ad6128 fixes this issue.
Use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
N/A
{
"github_reviewed": true,
"severity": "MODERATE",
"cwe_ids": [
"CWE-918"
],
"nvd_published_at": "2025-01-16T19:15:28Z",
"github_reviewed_at": "2025-01-16T23:08:32Z"
}