CVE-2026-57232: Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
Summary
The Feed Reader front-end module passes RSS feed URLs from its configuration directly to $this->feedIo->read($url) without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loopback addresses, causing the server to fetch those resources unconditionally. Confirmed live: the server successfully reaches the internal MySQL database container and its own loopback Apache instance.
---
Details
In core-bundle/src/Controller/FrontendModule/FeedReaderController.php, the getResponse() function iterates over the configured feed URLs and passes each one directly to the HTTP client with no validation:
php // Line 50-55 foreach (StringUtil::trimsplit('[\n\t ]', trim($model->rssfeed)) as $url) { try { $feed = $this->cache->get( 'feedreader'.$model->id.''.md5($url), function (ItemInterface $item) use ($url, $model) { $readerResult = $this->feedIo->read($url, new Feed()); // <-- no validation
The DCA field definition for rssfeed in tlmodule.php carries no URL scheme or host validation: php 'eval' => array('mandatory'=>true, 'decodeEntities'=>true, 'style'=>'height:60px')
The HTTP client is wired as @psr18.httpclient (Symfony HttpClient) with no SSRF protection configured (NoPrivateNetworkHttpClient is not used).
---
Impact
This is a CWE-918 (SSRF) vulnerability. A backend user with module-edit access can:
1. Enumerate internal network services -- probe any IP/port on the internal network by observing response times and error messages 2. Reach internal APIs -- access unauthenticated services inside the Docker/Kubernetes network (databases, caches, admin panels) 3. Steal cloud metadata credentials -- on AWS, fetch http://169.254.169.254/latest/meta-data/iam/security-credentials/ to obtain IAM role credentials (IMDSv1 has no authentication) 4. Pivot to internal infrastructure -- use the server as a proxy to interact with services not exposed to the public internet
Confirmed in live testing: the server successfully connected to the internal MySQL container (172.19.0.3:3306) and retrieved a full HTTP response from its own loopback interface (127.0.0.1:80).
---
Remediation
1. Use NoPrivateNetworkHttpClient -- wrap the injected HTTP client with Symfony's built-in SSRF protection before passing it to feedIo: php use Symfony\Component\HttpClient\NoPrivateNetworkHttpClient;
$safeClient = new NoPrivateNetworkHttpClient($this->httpClient); This blocks all RFC-1918, loopback, and link-local addresses at the HTTP client level.
2. Validate URL scheme and host -- before calling feedIo->read(), parse the URL and reject anything that is not http:// or https:// with a public routable IP or hostname.
3. Configure the DCA field -- add 'rgxp' => 'url' and a custom validation callback to tlmodule.rssfeed to reject non-public URLs at save time.
Other sources
Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or private-address validation, allowing a backend user with module-edit permissions to make the server request internal network services, loopback addresses, or cloud metadata endpoints. In core-bundle/src/Controller/FrontendModule/FeedReaderController.php, the getResponse() function iterates over the configured feed URLs and passes each one directly to the HTTP client (via $this->feedIo->read($url, new Feed())) with no validation, while the DCA field definition for rssfeed in tlmodule.php carries no URL scheme or host validation and the HTTP client is wired as @psr18.httpclient (Symfony HttpClient) with no SSRF protection configured, since NoPrivateNetworkHttpClient is not used. This issue is fixed in versions 5.3.48.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.7.9 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.3.48 - Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 5.7.9 - Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 5.3.48 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 5.3.48 - Configuration
Configure the DCA field tl_module.rss_feed with 'rgxp' => 'url' and a custom validation callback that rejects non-public URLs at save time.
Contao Feed Reader module tl_module.rss_feed validation = rgxp=url with a custom validation callback rejecting non-public URLs - Configuration
Wrap the injected HTTP client with Symfony's NoPrivateNetworkHttpClient before passing it to feedIo; this blocks RFC-1918, loopback, and link-local addresses.
Feed Reader HTTP client HTTP client SSRF protection = NoPrivateNetworkHttpClient
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57232?
CVE-2026-57232 has a low severity rating of 3.1.
What type of vulnerability is CVE-2026-57232?
CVE-2026-57232 is a Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2026-57232?
To fix CVE-2026-57232, ensure that the Feed Reader module validates RSS feed URLs for scheme and private-address restrictions.
Which versions of Contao are affected by CVE-2026-57232?
CVE-2026-57232 affects Contao versions 5.3.35 through 5.3.47 and 5.7.0-RC1 through 5.7.8.
What component of Contao is vulnerable in CVE-2026-57232?
The vulnerable component in CVE-2026-57232 is the Feed Reader front-end module.