Executive brief
Synology Chat Server contains a server-side request forgery vulnerability in its webhook functionality that allows authenticated users to access non-sensitive internal information. An attacker with valid credentials can exploit this to probe internal network resources and bypass security controls designed to restrict outbound requests.
Technical details
This is a server-side request forgery (SSRF) vulnerability (CWE-918) in the webhook component of Synology Chat Server prior to version 2.4.5-22148. The vulnerability requires authentication and network access but no user interaction. An authenticated remote attacker can manipulate webhook requests to access or retrieve non-sensitive information from internal systems that would normally be restricted. The vulnerability has been patched in version 2.4.5-22148 and later.
Affected products
- Synology Chat Server before 2.4.5-22148
Timeline
- 2026-05-26: disclosed: Initial public release of Synology-SA-26:10
- 2026-08-28: disclosed: Vulnerability details disclosed
- 2026-05-26: patched: Fixed in version 2.4.5-22148 or above