Executive brief
A security vulnerability exists in the installation component of perfree go-fastdfs-web, a web-based management interface for the fastdfs distributed file system. An attacker can exploit this flaw to force the server to make unauthorized requests to internal or external network resources. This could lead to the exposure of sensitive internal data or allow the attacker to bypass network security controls to reach other systems.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in perfree go-fastdfs-web versions up to and including 1.3.7. The flaw is located in the 'checkServer' function within the '/install/checkServer' file of the Installation Endpoint component. A remote, unauthenticated attacker can provide malicious input to this function, causing the server to initiate network requests to arbitrary locations. This can be used to scan internal networks, access local services, or exfiltrate data. A public exploit has been disclosed, and as of the advisory date, the vendor has not responded to reports of the vulnerability.
Affected products
- perfree go-fastdfs-web up to 1.3.7
Timeline
- 2026-06-06: disclosed: Vulnerability disclosed via VulDB and NVD
- 2026-06-06: advisory