Executive brief
Dub is a link attribution platform used by marketing teams to track and manage URLs. An unauthenticated attacker can exploit a flaw in the metatags edge endpoint to force the Dub server to make HTTP requests to internal systems or cloud metadata services, potentially exposing sensitive infrastructure information or cloud credentials without any authentication requirement.
Technical details
A server-side request forgery (SSRF) vulnerability exists in Dub's metatags edge endpoint, which fetches and processes URLs supplied by the caller. The endpoint fails to implement URL validation, denylist filtering, or authentication checks before making HTTP requests. This allows unauthenticated remote attackers to specify arbitrary URLs (internal, private, or cloud metadata endpoints) that the server will request on their behalf. An attacker can leverage this to scan internal services, access cloud metadata endpoints (e.g., AWS IMDSv1), or exfiltrate data from systems that trust the Dub server's IP address.
Affected products
- Dub Dub as of 2026-07-10
Timeline
- 2026-08-11: disclosed: CVE-2026-72552 published