Answer in brief
CVE-2026-57232 records a Low severity (CVSS 3.1) vulnerability in Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module. The current sources do not mark it as known exploited. The current feed maps contao/contao (composer), contao/contao (composer), contao/core-bundle (composer), contao/core-bundle (composer) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 3.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps contao/contao (composer), contao/contao (composer), contao/core-bundle (composer), contao/core-bundle (composer) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| contao/contaocomposer | >=5.3.35,<5.3.48 | 5.3.48 |
| contao/contaocomposer | >=5.4.0,<5.7.9 | 5.7.9 |
| contao/core-bundlecomposer | >=5.3.35,<5.3.48 | 5.3.48 |
| contao/core-bundlecomposer | >=5.4.0,<5.7.9 | 5.7.9 |
| contao/contaopackagist | >=5.3.35 <5.3.48 | 5.3.48 |
| contao/contaopackagist | >=5.4.0 <5.7.9 | 5.7.9 |
| contao/core-bundlepackagist | >=5.4.0 <5.7.9 | 5.7.9 |
| contao/core-bundlepackagist | >=5.3.35 <5.3.48 | 5.3.48 |
Published upstream
Jul 31, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Aug 3, 2026
### Summary The Feed Reader front-end module passes RSS feed URLs from its configuration directly to `$this->feedIo->read($url)` without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loopback addresses, causing the server to fetch those resources unconditionally. Confirmed live: the server successfully reaches the internal MySQL database container and its own loopback Apache instance. --- ### Details In `core-bundle/src/Controller/FrontendModule/FeedReaderController.php`, the `getResponse()` function iterates over the configured feed URLs and passes each one directly to the HTTP client with no validation: ```php // Line 50-55 foreach (StringUtil::trimsplit('[\n\t ]', trim($model->rss_feed)) as $url) { try { $feed = $this->cache->get( 'feed_reader_'.$model->id.'_'.md5($url), function (ItemInterface $item) use ($url, $model) { $readerResult = $this->feedIo->read($url, new Feed()); // <-- no validation ``` The DCA field definition for `rss_feed` in `tl_module.php` carries no URL scheme or host validation: ```php 'eval' => array('mandatory'=>true, 'decodeEntities'=>true, 'style'=>'height:60px') ``` The HTTP client is wired as `@psr18.http_client` (Symfony HttpClient) with no SSRF protection configured (`NoPrivateNetworkHttpClient` is not used). --- ### Impact This is a CWE-918 (SSRF) vulnerability. A backend user with module-edit access can: 1. **Enumerate internal network services** -- probe any IP/port on the internal network by observing response times and error messages 2. **Reach internal APIs** -- access unauthenticated services inside the Docker/Kubernetes network (databases, caches, admin panels) 3. **Steal cloud metadata credentials** -- on AWS, fetch `http://169.254.169.254/latest/meta-data/iam/security-credentials/` to obtain IAM role credentials (IMDSv1 has no authentication) 4. **Pivot to internal infrastructure** -- use the server as a proxy to interact with services not exposed to the public internet Confirmed in live testing: the server successfully connected to the internal MySQL container (`172.19.0.3:3306`) and retrieved a full HTTP response from its own loopback interface (`127.0.0.1:80`). --- ### Remediation 1. **Use `NoPrivateNetworkHttpClient`** -- wrap the injected HTTP client with Symfony's built-in SSRF protection before passing it to feedIo: ```php use Symfony\Component\HttpClient\NoPrivateNetworkHttpClient; $safeClient = new NoPrivateNetworkHttpClient($this->httpClient); ``` This blocks all RFC-1918, loopback, and link-local addresses at the HTTP client level. 2. **Validate URL scheme and host** -- before calling `feedIo->read()`, parse the URL and reject anything that is not `http://` or `https://` with a public routable IP or hostname. 3. **Configure the DCA field** -- add `'rgxp' => 'url'` and a custom validation callback to `tl_module.rss_feed` to reject non-public URLs at save time.
Quoted source text, attributed separately from HOL analysis.