{"id":"CVE-2024-52594","aliases":["GHSA-4ff6-858j-r822","GO-2025-3396"],"url":"https://o3.security/vulnerability/CVE-2024-52594","summary":"Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib","details":"Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.","published":"2025-01-16T18:57:29.333Z","modified":"2026-07-15T01:49:08.645264094Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00338,"percentile":0.26364,"asOf":"2026-08-04"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/matrix-org/gomatrixserverlib","fixedVersion":"0.0.0-20250116181547-c4f1e01eab0d"}],"fix":{"url":"https://github.com/matrix-org/gomatrixserverlib/commit/c4f1e01eab0dd435709ad15463ed38a079ad6128","label":"matrix-org/gomatrixserverlib@c4f1e01"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52594.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/gomatrixserverlib/security/advisories/GHSA-4ff6-858j-r822"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52594"},{"type":"FIX","url":"https://github.com/matrix-org/gomatrixserverlib/commit/c4f1e01eab0dd435709ad15463ed38a079ad6128"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:08.645264094Z"}}