austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF)
30
Low Risk
Canvas validates a webhook URL's hostname by resolving it once and checking that every A and AAAA address is public, then delivers the webhook through a separate HTTP client call that resolves the same hostname again independently. A hostname under externally controlled DNS can resolve to a public address during validation and to a private or internal address during delivery, letting the outbound webhook request reach internal network targets. The fix resolves both A and AAAA records up front, rejects any private or mixed resolution, and pins the delivery connection to the validated address with CURLOPT_RESOLVE while enforcing HTTPS and failing closed when curl pinning is unavailable.
You are affected if you are using a version that falls within the vulnerable range and you use Canvas's webhook delivery feature.
austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.0.0 - 7.1.0.
Upgrade the austintoddj/canvas library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.