Executive brief
Lemmy, a federated social media platform, is vulnerable to a security flaw where it can be tricked into accessing internal network resources. By posting a link to a specially crafted webpage, an attacker can force the server to fetch and cache images from private internal addresses that should not be accessible from the internet. This could lead to the exposure of sensitive internal data or images to unauthorized users.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Lemmy's link preview generation logic. While the initial post URL is validated against internal IP ranges, the application fails to validate secondary URLs extracted from 'og:image' Open Graph tags. An authenticated attacker can provide a public URL that contains an 'og:image' tag pointing to an internal IP or loopback address (e.g., 127.0.0.1). Lemmy's backend then instructs the pict-rs service to fetch this internal resource, effectively bypassing network boundaries. The fetched internal image is then cached as a thumbnail and served back to the attacker. This issue is resolved in version 0.19.18 by implementing IP validation on the extracted image URLs.
Affected products
- LemmyNet lemmy_api_common < 0.19.18
Timeline
- 2026-04-20: patched: Release v0.19.18 published
- 2026-04-24: advisory: GitHub Advisory GHSA-h6hf-9846-xwrq published
- 2026-05-08: advisory: NVD published CVE-2026-42181
References
- https://github.com/LemmyNet/lemmy/security/advisories/GHSA-h6hf-9846-xwrq
- https://github.com/LemmyNet/lemmy/commit/9ffe586dafac1a46acf17edf90e0165e5503b2f1
- https://join-lemmy.org/news/2026-04-20_-_Lemmy_Release_v0.19.18
- https://github.com/LemmyNet/lemmy/releases/tag/0.19.18
- https://api.github.com/repos/LemmyNet/lemmy/security-advisories/GHSA-h6hf-9846-xwrq