Junglewise Threat Intelligence

Novu application-generic SSRF bypass via CGNAT address range

Severity: medium · CVSS 6.8 · Published 2026-07-28

Vendors: Novu, npm.

Executive brief

Novu, an open-source notification infrastructure platform, contains a security flaw in how it validates web addresses for automated tasks like webhooks and workflow HTTP requests. The system's safety filter fails to block a specific range of internal network addresses (CGNAT), which could allow an attacker to force the server to send requests to sensitive internal services. In cloud environments like Alibaba Cloud, this could lead to the exposure of private server metadata or unauthorized access to internal infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `validateUrlSsrf` guard within `@novu/application-generic`. The vulnerability stems from an incomplete regex-based deny-list in `isPrivateIp(...)` which omits the `100.64.0.0/10` shared address space (CGNAT). An attacker can exploit this by configuring a Workflow HTTP request step or a Webhook filter condition with a URL pointing to internal services, such as the Alibaba Cloud metadata endpoint at `100.100.100.200`. The guard resolves the hostname but permits the request because the resulting IP is not in the hardcoded private range list. The issue is addressed in version 3.17.0 by improving IP validation.

Affected products

  • Novu @novu/application-generic < 3.17.0

Timeline

  • 2026-06-07: advisory: Initial GitHub Advisory published
  • 2026-07-28: patched: Advisory updated with patch information for version 3.17.0

References

Related threats