CVE-2026-28508: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28508 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Idno (also known as Known), an open-source social publishing platform. A logic error in the API authentication flow allows any unauthenticated remote attacker to trivially bypass CSRF protection on the URL unfurl service endpoint (GET /service/web/unfurl?url=), enabling arbitrary outbound HTTP requests from the server. All versions up to and including 1.6.3 are affected; the issue was patched in version 1.6.4, released March 1, 2026. It carries a CVSS v3.1 base score of 8.6 (High) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory).

Technical details

The root cause (CWE-918: Server-Side Request Forgery) stems from a logic error in Session::tryAuthUser() within Session.php, where setIsAPIRequest(true) is called unconditionally as soon as the HTTP headers X-IDNO-USERNAME and X-IDNO-SIGNATURE are present — before any HMAC credential verification occurs. This causes Actions::validateToken() to short-circuit and return true immediately, bypassing the CSRF token check in tokenGatekeeper(). The xhrGatekeeper() check is separately bypassed by simply including the X-Requested-With: XMLHttpRequest header, which any HTTP client can set. With both gatekeepers defeated, UnfurledUrl::unfurl() fetches the attacker-supplied URL using Webservice::file_get_contents() with no allowlist or blocklist for private/loopback/link-local address ranges, and returns the full response body as JSON. A detailed proof-of-concept is publicly available in the GitHub Security Advisory (GitHub Advisory).

Impact

An unauthenticated remote attacker can force the Idno server to issue HTTP requests to arbitrary destinations and retrieve the full response content, with no user interaction required. Critical attack scenarios include exfiltration of cloud instance metadata (e.g., AWS IMDSv1 IAM credentials at http://169.254.169.254/, GCP/Azure OAuth tokens), internal network reconnaissance to map services not exposed to the internet, access to localhost-restricted admin interfaces, and interaction with unauthenticated internal services such as Redis or Memcached. The vulnerability has high confidentiality impact on both the vulnerable system and subsequent systems in scope, with no integrity or availability impact (GitHub Advisory).

Exploitability

A public proof-of-concept exploit is available via the GitHub Security Advisory, requiring only three custom HTTP headers and a crafted GET request — making exploitation trivial for any attacker. No authentication, user interaction, or complex prerequisites are needed. There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.197%, reflecting low but non-negligible automated exploitation probability (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Idno/Known instances running versions ≤ 1.6.3 using search engines (Shodan, Censys) or by checking the version.idno file for version = '1.6.3' or earlier.
  2. Bypass xhrGatekeeper: Include the header X-Requested-With: XMLHttpRequest in the request to satisfy the XHR check.
  3. Bypass tokenGatekeeper via API flag: Include any non-empty values for X-IDNO-USERNAME and X-IDNO-SIGNATURE headers (e.g., X and X). This triggers setIsAPIRequest(true) before HMAC verification, causing validateToken() to return true immediately.
  4. Issue SSRF request: Send a GET request to the unfurl endpoint with the target internal URL as the url parameter:
    curl -s "http://<target>/service/web/unfurl?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/" \
      -H "X-Requested-With: XMLHttpRequest" \
      -H "X-IDNO-USERNAME: x" \
      -H "X-IDNO-SIGNATURE: x"
  5. Retrieve response: The server fetches the internal URL and returns the full response body as a JSON object, exposing cloud credentials, internal service content, or other sensitive data to the attacker (GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound HTTP requests from the Idno server to RFC 1918 addresses (10.x.x.x, 172.16-31.x.x, 192.168.x.x), loopback (127.0.0.1), or link-local addresses (169.254.169.254); outbound connections to cloud metadata service endpoints.
  • Logs: Web server access logs showing repeated GET requests to /service/web/unfurl?url= with internal or metadata service URLs as the url parameter; requests containing headers X-IDNO-USERNAME, X-IDNO-SIGNATURE, and X-Requested-With: XMLHttpRequest from external IP addresses.
  • Application Logs: PHP application logs showing UnfurledUrl::unfurl() calls with private/loopback/link-local target URLs.
  • Process: Unexpected outbound HTTP connections initiated by the PHP/web server process to internal network hosts or cloud metadata endpoints (GitHub Advisory).

Mitigation and workarounds

Upgrade all Idno/Known installations to version 1.6.4 or later immediately, as this release fixes the CSRF bypass by moving setIsAPIRequest(true) to after successful HMAC verification in Session.php (GitHub Release). As a defense-in-depth measure, the advisory recommends adding URL validation in the unfurl function to reject requests to RFC 1918, loopback, and link-local address ranges using PHP's FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE flags. Additionally, consider implementing network-level egress filtering on the server to restrict outbound HTTP connections to only necessary external hosts, limiting the blast radius of any SSRF exploitation (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher anuraagbaishya, who noted that the security contact email address listed by the Idno project (security@idno.co) was non-functional at the time of disclosure. The advisory was published by project maintainer benwerd on March 1, 2026, alongside the patched release. A technical write-up was published at infinitsec.net shortly after disclosure, and the CVE received automated coverage from vulnerability tracking services including Vulners, VulDB, and CVEFeed (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management