fix: stop image proxy following redirects past the SSRF guard refs GHSA-v2qc-p8cq-g4pc

The proxy= handler in web/views/image.php validates the resolved address
of the URL host against FILTER_FLAG_NO_RES_RANGE, then fetches with
fopen() using PHP's default follow_location=1. A host that passes the
check could answer 302 to 127.0.0.1 (or ::1, 169.254.169.254) and the
stream wrapper would request it, returning the loopback content.

Set follow_location to 0 in the http stream context so a 3xx is not
followed. The same $opts is reused for the digest auth retry, so both
fetches are covered. Camera discovery has no need for redirects.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit ec71edad630ff614eaae499146d33fd780449715)
This commit is contained in:
Isaac Connor committed 2026-09-24 19:46:37 -04:00
1 parent 911362d873
commit 21f88bfcee
1 file changed
+4 -1
+4 -1
View File
@@ -117,7 +117,10 @@ if (!empty($_REQUEST['proxy'])) {
'http'=>array(
'method'=>$method,
#'header'=>"Accept-language: en\r\n" .
'ignore_errors' => true
'ignore_errors' => true,
// The SSRF guard above only validated $host. Following a redirect would
// connect to a Location the guard never checked (e.g. 127.0.0.1).
'follow_location' => 0,
#"Cookie: foo=bar\r\n"
),
'ssl'=>array(