Description
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure (Remote Authenticated)
Action: Assess Impact
AI Analysis

Impact

A server‑side request forgery flaw exists in the webhook handling of Synology Chat Server versions older than 2.4.5‑22148. The application will forward requests to arbitrary URLs supplied by a remote authenticated user, resulting in the disclosure of non‑sensitive data that can be accessed from within the network, such as internal addresses or basic configuration information. This weakness is classified as CWE‑918.

Affected Systems

Synology Chat Server components running any build prior to 2.4.5‑22148 are susceptible. The vulnerability applies to all installations of the chat server that have the webhook feature enabled in those versions.

Risk and Exploitability

The CVSS score of 4.3 places the issue in the moderate range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread, automated exploitation has not been observed. Attackers need to be authenticated to the chat service to trigger the flaw and would not gain code execution or privilege escalation, but could use the SSRF capability to probe internal resources and obtain non‑sensitive information.

Generated by OpenCVE AI on August 28, 2026 at 12:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Synology Chat Server to version 2.4.5‑22148 or later to remove the SSRF flaw.
  • If an immediate update is not possible, disable the webhook feature for all users or restrict webhook configuration to trusted administrators only.
  • Restrict outbound HTTP/HTTPS traffic from the chat server to untrusted destinations, limiting the attack surface for potential SSRF exploitation.

Generated by OpenCVE AI on August 28, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology synology Chat Server
Vendors & Products Synology
Synology synology Chat Server

Fri, 28 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title Synology Chat Server SSRF via Webhook Allows Authenticated Users to Retrieve Non‑Sensitive Information

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Synology Chat Server SSRF via Webhook Allows Authenticated Users to Retrieve Non‑Sensitive Information

Fri, 28 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Synology Synology Chat Server
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-08-28T11:03:53.629Z

Reserved: 2026-05-25T02:03:55.583Z

Link: CVE-2026-9491

cve-icon Vulnrichment

Updated: 2026-08-28T11:03:48.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-28T08:16:58.953

Modified: 2026-09-01T20:54:51.287

Link: CVE-2026-9491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:22:00Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)