Executive brief
Prefect is a workflow orchestration platform used to manage and automate data pipelines. A security vulnerability in its notification system could allow an attacker to bypass security filters and force the system to send requests to internal or restricted network locations. This could lead to the exposure of internal service information or unauthorized access to private infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Prefect's Webhook and Notification components due to a Time-of-Check Time-of-Use (TOCTOU) flaw in the 'validate_restricted_url' function. An attacker can use DNS rebinding to provide a URL that resolves to a legitimate public IP during the validation phase but resolves to a restricted internal IP during the execution phase. This bypasses restricted URL filters, allowing the application to make requests to internal services. The attack requires network access and has high complexity due to the timing requirements of DNS rebinding. The issue is addressed in version 3.6.28.dev2.
Affected products
- PrefectHQ prefect < 3.6.28.dev2
Timeline
- 2026-05-04: disclosed
- 2026-05-04: advisory
- 2026-05-22: patched