Gomatrixserverlib Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Gomatrixserverlib, a Go library for Matrix federation. This vulnerability allows the library to access and serve content from a private network, under certain conditions. The issue is present in versions of Gomatrixserverlib through dbd5f31fefc031633c3418165e4ef6d343e03999.

Impact

Exploitation of this vulnerability allows for server-side request forgery, enabling the library to access and serve content from private networks it can reach.

Remediation

Users are advised to upgrade to the version containing the patch. For those unable to upgrade, it is recommended to use a local firewall to restrict the network segments and hosts that the service using Gomatrixserverlib can access.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.8
exploitability
5.9
remediation
7.9
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.