CVE-2026-33655
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
Description
## Summary The default SSRF protection configuration did not apply IP filtering to hostnames. With `ApplyIPFilterForDomain` disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the resolved IP address. Authenticated users could configure notification URLs for Webhook, Bark, or Gotify notifications and point a hostname at an internal or metadata IP address. ## Impact A regular authenticated user could cause the server to send notification requests to internal HTTP services reachable from the deployment network. Depending on the target environment, this could expose sensitive internal data through timing, errors, or response-dependent behavior. The issue is rated High. ## Affected versions Versions before `v0.12.0-alpha.1` are affected. The previous affected range of `<= v0.11.4-alpha.4` was too narrow because the unsafe default remained present until the `v0.12.0-alpha.1` fix. ## Patches This issue is fixed in `v0.12.0-alpha.1`. The default fetch setting now sets `ApplyIPFilterForDomain: true`, causing hostname destinations to be resolved and checked against the configured IP filtering rules during URL validation. This patch addresses the unresolved-hostname bypass for the affected notification URL paths. It does not mark the separate DNS rebinding advisory as fixed, because connection-time IP enforcement is tracked separately. ## Workarounds If upgrading immediately is not possible, explicitly enable `ApplyIPFilterForDomain`, restrict notification URL domains with an allowlist, disable user-configurable notification URLs where practical, and enforce outbound network filtering at the host or network layer. ## Resources - Fixed by commit `20399d3c8fcb4e3649d53163eb11940fd6763743`. - Relevant code paths: `setting/system_setting/fetch_setting.go`, `common/ssrf_protection.go`, `service/webhook.go`, and `service/user_notify.go`.
How to fix CVE-2026-33655
To remediate CVE-2026-33655, upgrade the affected package to a fixed version below.
- —upgrade to 0.12.0-alpha.1 or later
Is CVE-2026-33655 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.