Executive brief
Apache Fesod, a library used for processing spreadsheets, contains a vulnerability in its image handling component. An attacker can provide a malicious image URL that forces the server to make unauthorized requests to internal systems or restricted network resources. This could lead to the exposure of sensitive internal data or information about the organization's private network infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet. The issue stems from improper validation of user-supplied URLs when fetching images for spreadsheet conversion. A remote, unauthenticated attacker can exploit this by providing a crafted URL, causing the server to initiate outbound network requests to internal or restricted resources (CWE-918). This can be used to bypass network segmentation or perform internal port scanning. The fix, introduced in version 2.0.2-incubating, implements a URL scheme policy, CIDR block restrictions for private networks, and redirect limits.
Affected products
- Apache Software Foundation Fesod (Incubating) fesod-sheet < 2.0.2-incubating
Timeline
- 2026-05-14: patched: Pull request #917 merged to implement URL scheme policy
- 2026-05-30: advisory: Release 2.0.2-incubating published
- 2026-06-01: disclosed: Public disclosure via oss-security mailing list and GHSA