CVE-2025-22952
NixOS vulnerability analysis and mitigation

Overview

Elestio memos v0.23.0 contains a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to access internal network resources. The vulnerability was discovered in February 2025 and affects both elestio/memos:latest and neosmemo/memos:latest Docker images (GitHub Issue).

Technical details

The vulnerability exists in the GetLinkMetadata API endpoint due to insufficient validation of user-supplied URLs in the memos-main\plugin\httpgetter\html_meta.go file. The http.Get(urlStr) function within GetHTMLMeta does not properly restrict access to internal network resources, allowing attackers to make requests to arbitrary internal hosts and ports (GitHub Issue).

Impact

This vulnerability enables attackers to access internal network assets, perform internal network scanning, sniff web services on the internal network, and potentially access sensitive internal endpoints. Attackers can exploit this to gather information about the internal network infrastructure and potentially access restricted services (GitHub Issue).

Exploitability

The vulnerability can be exploited by sending specially crafted requests to the GetLinkMetadata API endpoint. An attacker can specify internal network URLs to probe internal services and ports. The vulnerability has been demonstrated to work against both HTTP and FTP services running on internal networks (GitHub Issue).

Mitigation and workarounds

A fix has been implemented in pull request #4428 to prevent redirect attacks through the GetLinkMetadata API. The patch adds additional validation to prevent attackers from exploiting redirects to access internal network resources (GitHub PR). Users should upgrade to the latest version that includes this security fix.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management