Executive brief
mosparo is an open-source spam protection tool used to secure online forms. A vulnerability in the way it handles automatic rule updates allows a project editor to force the server to make requests to internal network locations that should be private. This could allow an attacker to map out internal infrastructure, probe local services, or access sensitive internal data that is not intended to be exposed to the internet.
Technical details
A stored Server-Side Request Forgery (SSRF) vulnerability exists in mosparo's automatic rule package feature. A project member with 'editor' privileges can provide a malicious URL for rule updates. The server's HttpClient follows HTTP/HTTPS redirects by default and fails to validate or restrict destinations to public IP addresses, allowing redirects to loopback (127.0.0.1) or private RFC1918 addresses. By observing the error messages returned in the UI (such as hash verification failures versus transport errors), an attacker can use the server as an HTTP probing oracle to discover internal services and verify the existence of internal paths. The vulnerability is fixed in version 1.4.13.
Affected products
- mosparo mosparo < 1.4.13
Timeline
- 2026-04-28: advisory: GitHub Security Advisory published by vendor
- 2026-05-12: disclosed: CVE-2026-41195 published to NVD