Skip to content

SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins

Moderate
markuslf published GHSA-96fx-pqc3-28xv Jul 7, 2026

Software

Linuxfabrik/monitoring-plugins

Affected versions

<= 6.0.0

Patched versions

>= 7.0.0

Description

Summary

The redfish-* checks discover sub-resources by following @odata.id hypermedia links returned by the monitored controller (BMC). Each link was turned into the next request URL by string concatenation onto the operator-supplied base URL (f'{args.URL}{member["@odata.id"]}'), with no validation that @odata.id is a server-relative path. A malicious or compromised BMC can return a value beginning with @ (or //) so that the concatenated string carries an attacker-chosen authority, e.g. https://bmc + @evil/x = https://bmc@evil/x (host evil). The plugin then issues an authenticated request (Redfish X-Auth-Token session token, or HTTP Basic header) to the attacker-named host.

Impact

A malicious or compromised monitored BMC can coerce the monitoring host into issuing authenticated requests to arbitrary reachable hosts and ports (a blind SSRF pivot into the management network) and can exfiltrate the Redfish auth header. Requires a controller that returns hostile responses; the base URL is the documented path-less form (--url=https://bmc), so no extra misconfiguration is needed. Present since the redfish plugins were introduced.

Patches

Fixed in v7.0.0. Every response-supplied link is now built through lib.redfish.build_url(), which rejects any @odata.id that is not a single-slash-rooted relative path and pins scheme and host to the operator-supplied base URL, so a response can never redirect the request to another host (monitoring-plugins commit ffb0a81, linuxfabrik-lib adds the helper).

Severity

Moderate

CVE ID

CVE-2026-67436

Weaknesses

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. Learn more on MITRE.

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. Learn more on MITRE.

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Learn more on MITRE.

Credits