From 21f88bfcee8f619b7a2e85330fbbde0d8df201c8 Mon Sep 17 00:00:00 2001 From: Isaac Connor Date: Thu, 24 Sep 2026 19:44:22 -0400 Subject: [PATCH] fix: stop image proxy following redirects past the SSRF guard refs GHSA-v2qc-p8cq-g4pc The proxy= handler in web/views/image.php validates the resolved address of the URL host against FILTER_FLAG_NO_RES_RANGE, then fetches with fopen() using PHP's default follow_location=1. A host that passes the check could answer 302 to 127.0.0.1 (or ::1, 169.254.169.254) and the stream wrapper would request it, returning the loopback content. Set follow_location to 0 in the http stream context so a 3xx is not followed. The same $opts is reused for the digest auth retry, so both fetches are covered. Camera discovery has no need for redirects. Co-Authored-By: Claude Opus 5.5 (cherry picked from commit ec71edad630ff614eaae499146d33fd780449715) --- web/views/image.php | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/web/views/image.php b/web/views/image.php index a4fc7ba5b..1df158542 100644 --- a/web/views/image.php +++ b/web/views/image.php @@ -117,7 +117,10 @@ if (!empty($_REQUEST['proxy'])) { 'http'=>array( 'method'=>$method, #'header'=>"Accept-language: en\r\n" . - 'ignore_errors' => true + 'ignore_errors' => true, + // The SSRF guard above only validated $host. Following a redirect would + // connect to a Location the guard never checked (e.g. 127.0.0.1). + 'follow_location' => 0, #"Cookie: foo=bar\r\n" ), 'ssl'=>array(