T09 · Insecure Skill Coding Practices
- Location
references/worker-patterns.md:58- Finding
Unrestricted Webhook Destination Enables Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
references/worker-patterns.md:58-63
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: Highelixir @impl Oban.Worker def perform(%Oban.Job{args: args, attempt: attempt}) do %{"url" => url, "event" => event, "payload" => payload} = args headers = build_headers(args) case Req.post(url, json: payload, headers: headers, receive_timeout: 25_000) doTechnical Analysis
The worker obtains the destination URL directly from attacker-influenceable Oban job arguments and passes it to
Req.post/2without validating the scheme, hostname, port, resolved IP address, or redirect destination.If an untrusted user can enqueue a job or influence its arguments, the application server can be induced to issue requests to destinations unavailable to the attacker directly. Relevant targets include:
- Loopback services such as
127.0.0.1or::1 - Private network addresses
- Link-local addresses and cloud instance metadata endpoints
- Internal administrative APIs
- Services exposed through DNS rebinding or redirects
A request timeout limits request duration but does not prevent SSRF.
Attack Path
- An attacker gains the ability to create or influence a webhook delivery job.
- The attacker places an internal or otherwise restricted destination in the job's
"url"argument. - Oban executes the worker in the trusted application environment.
Req.post/2sends the supplied payload to the attacker-selected destination.- The attacker uses response-dependent behavior, logs, or observable side effects to probe or interact with the target.
- If the target is a metadata service or privileged internal API, the request may expose credentials or perform sensitive operations.
Impact Assessment
Exploitation provides access to network resources reachable by the application worker. Depending on network placement and target behavior, ...[truncated 336 chars]
- Loopback services such as
- Remediation
View remediation
Remediation Suggestions
- Store only a trusted webhook or subscriber identifier in job arguments.
- Resolve the destination URL from an application-controlled database record at execution time.
- Require an approved scheme such as HTTPS.
- Allowlist expected hostnames and ports where practical.
- Resolve hostnames and reject loopback, private, link-local, multicast, and reserved addresses for both IPv4 and IPv6.
- Revalidate the resolved address immediately before connecting to reduce DNS-rebinding risk.
- Disable redirects or validate every redirect destination using the same policy.
- Apply outbound firewall or proxy controls that deny access to internal and metadata networks.
- Restrict which application roles may create webhook subscriptions or enqueue webhook jobs.
- Add tests covering encoded IP addresses, IPv6, redirects, DNS rebinding, and cloud metadata endpoints.
