Intel

AIKIDO-2026-26845

austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-2v46-cgmc-v9xr Published Yesterday

30

Low Risk

This Affects:

PHPaustintoddj/canvas
7.0.0 - 7.1.0
Fixed in 7.1.1
Are you affected? Scan for Free

TL;DR

Canvas validates a webhook URL's hostname by resolving it once and checking that every A and AAAA address is public, then delivers the webhook through a separate HTTP client call that resolves the same hostname again independently. A hostname under externally controlled DNS can resolve to a public address during validation and to a private or internal address during delivery, letting the outbound webhook request reach internal network targets. The fix resolves both A and AAAA records up front, rejects any private or mixed resolution, and pins the delivery connection to the validated address with CURLOPT_RESOLVE while enforcing HTTPS and failing closed when curl pinning is unavailable.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use Canvas's webhook delivery feature.

Background info

austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.0.0 - 7.1.0.

How to fix this

Upgrade the austintoddj/canvas library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform