Uh oh!
There was an error while loading. Please reload this page.
Add CURLOPT_RESOLVE and safer following of HTTP redirections - #76
Merged
Conversation
Related to: * FreshRSS/FreshRSS#8400 Fixes upstream: * simplepie#968 Co-authored-by: Inverle <inverle@proton.me>
This was referenced May 25, 2026
Inverle
reviewed
May 26, 2026
Uh oh!
There was an error while loading. Please reload this page.
Inverle
approved these changes
May 26, 2026
Uh oh!
There was an error while loading. Please reload this page.
Alkarex added a commit
to Inverle/FreshRSS
that referenced
this pull request
May 26, 2026
Alkarex added a commit
that referenced
this pull request
Jun 27, 2026
…-origin) (#78) * Improve SimplePie redirects (POST to GET, remove authentication cross-origin) Follow-up of #76FreshRSS/FreshRSS#8400 * PHP 7.2+ compatibility * Normalize URLs to lowercase when parsing * Fix wrong URL printed in error message * Same logic for fsockopen * Also unset `CURLOPT_USERPWD` during redirects * Add infinite redirects for the `fsockopen()` path too * Draft rework CURLOPT_FOLLOWLOCATION * A bit of documentation * Minor doc * Move curl_close * composer run fix --------- Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Alkarex added a commit
to FreshRSS/FreshRSS
that referenced
this pull request
Jun 28, 2026
* Add SSRF mitigations using `filter_var` and `CURLOPT_RESOLVE` The idea is to prevent FreshRSS from sending any HTTP requests to internal services, except for the ones that are explicitly allowed in the config. Based on https://github.com/moodle/moodle/blob/6e82b46a480826d1a85394d9e5087f7d82d1dd52/lib/filelib.php#L3818 and https://github.com/symfony/symfony/blob/8.1/src/Symfony/Component/HttpClient/NoPrivateNetworkHttpClient.phpFreshRSS/simplepie#76FreshRSS/simplepie#78 * Add allowlist setting in Web UI * make readme * Update app/i18n/fr/admin.php Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr> * make readme again * make readme * Further work Still WIP and needs testing etc. * Readd previous if check for domain combination allowlist * Turn POST to GET after redirect * Improve * Update config.default.php Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr> * make readme * Skip SSRF check if `CURLOPT_PROXY` is set * make readme * Fix `!empty()` mistake * Respect max redirects feed option when fetching with `httpGet()` * Respect max redirects during SimplePie fetching + fix bypass bypass fix: `CURLOPT_FOLLOWLOCATION` was moved below so that emulated redirects are enforced. * Avoid FreshRSS and Minz code in SimplePie #8400 (comment) * Corrected hook code * phpdoc wrong return type * Add CIDR support in allowlist * Implement simple DNS caching * Suppress `dns_get_record()` warnings * A bit of proof-reading * Minor typo * Fix proxy logic * Fix HTTP POST redirect logic * Proofread checkCIDR Add fixes for several situations * Remove credentials from URL in logs * Ensure `CURLOPT_FOLLOWLOCATION` is `false` by setting it at the end * Fix codesniffer long line * Fix potential bypass due to wrong return value If there were no records returned by `dns_get_record()`, no overrides to `CURLOPT_RESOLVE` would get passed, and a potential bypass could occur, when cURL would try to resolve the domain by itself. * Put the URL at the end in logs * Add documentation and environment variable support * make readme * Fix wrong behavior in case of IP * Fix duplicate selector in CSS * Minor type check change * i18n fr, en * Minor type check change * Fix whitespace i18n fr * make fix-all * Fix `$ips_ok` not being returned after domain records were cached * make readme * PHPStan fix * make readme * Minor syntax in SimplePie * Only return `null` if no allowed IPs were found * Add wildcard *, help message * Consistent docs with help message * i18n: pl * SimplePie compatibility PHP 7.2 * make fix-all * Sync SimplePie * FreshRSS/simplepie#76 * 💥 Breaking change in the Changelog * Document `INTERNAL_HOST_ALLOWLIST` in Docker docs * Remove `Cookie` and `Authorization` headers in `httpGet()` during cross-origin redirect * Minor whitespace And same comment convention than below * Remove authentication headers and change POST to GET on redirect in SimplePie * Remove .local in Docker example * Fill in default ports when comparing URL origins * Remove .local from other places than the Docker example * Rewrite WebSub subscribe to use `httpGet()` * make fix-all * Also unset `CURLOPT_USERPWD` during redirects * phpcs fix * Always unset `CURLOPT_FOLLOWLOCATION` * Bump SimplePie FreshRSS/simplepie#78 * Update logic for CURLOPT_FOLLOWLOCATION * Fix PHPStan * Changelog fix security section * Update most common RSS Bridge case https://hub.docker.com/r/rssbridge/rss-bridge * Replace misleading 127.0.0.1:8080 example for Docker This does not make sense for a Docker container --------- Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Alkarex added a commit
that referenced
this pull request
Jul 23, 2026
* Allow restricting `CURLOPT_PROXY` with `get_curl_resolve_info()` Follow-up of #76FreshRSS/FreshRSS#8950 * Fix wrong for_proxy value returned from `get_curl_resolve_info()` * Minor CURLPROXY_HTTP * Implement suggestion * A few more fixes --------- Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related to:
filter_varandCURLOPT_RESOLVEFreshRSS#8400Fixes upstream: