Executive (CBA) summary :)
Security release: three fixes, no new features. Most installs can upgrade with no changes, but check the upgrade notes below if you use webhooks or custom OAuth behind a proxy, call the API from scripts using a login cookie, or embed Fider in an iframe.
Upgrade notes
Webhooks and custom OAuth behind an HTTP proxy. Webhooks and custom OAuth providers now check the destination IP at the moment they connect, and they ignore HTTP_PROXY / HTTPS_PROXY so that check can't be bypassed. If your server can only reach the internet through a proxy, set ALLOW_PRIVATE_NETWORK_TARGETS=true. That turns the check off and uses the proxy again. For a single-tenant install where the admins are trusted, this is fine.
More addresses are blocked for webhooks and custom OAuth. These are now rejected in addition to private and loopback addresses: CGNAT (100.64.0.0/10, which includes Tailscale addresses), 192.0.0.0/24, 198.18.0.0/15, multicast and reserved ranges, and IPv6 addresses that embed a private IPv4 (NAT64, 6to4, Teredo). If a webhook deliberately points at an internal service on one of these, set ALLOW_PRIVATE_NETWORK_TARGETS=true.
Scripts that call the API with a login cookie. POST, PUT and DELETE requests authenticated with a session cookie must now send Content-Type: application/json, or they get 403. Requests authenticated with an API key (Authorization: Bearer ...) on /api/ are not affected.
Fider in an iframe. Session cookies are now SameSite=Lax, so a Fider site embedded in an iframe on a different site will appear signed out inside the frame. Linking to Fider is unaffected.
Image uploads. Uploaded images are now checked against a memory budget before they're processed. Typical phone photos (12 MP) upload fine, but very large images are rejected with a message asking for a lower resolution. That's roughly over 30 MP for standard JPEGs, 14 MP for progressive JPEGs, or 28 MP for PNGs.
Security advisories
- GHSA-whx4-hxwq-qgjh: SSRF protection bypass via DNS rebinding (#1678)
- GHSA-p8j9-wxg9-qp34: SSRF protection bypass via IPv6 transition addresses (#1678)
- GHSA-xjr8-w967-4xjq: CSRF bypass via the
Acceptheader (#1676) - GHSA-7cw3-7xh9-529r: Denial of service via image decompression bomb (#1677)
Thanks to @carfeii, @ry2811, @tonghuaroot, @kaizhi888 and @bararchy for reporting these responsibly.
What's Changed
- Enforce the SSRF guard at connect time and block IPv6 transition addresses by @mattwoberts in #1678
- Require a preflight-forcing signal for write requests (CSRF hardening) by @mattwoberts in #1676
- Bound image decode memory before resizing (decompression bomb DoS) by @mattwoberts in #1677
Full Changelog: v0.37.0...v0.38.0