PYSEC-2026-1344
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Quick fix
PYSEC-2026-1344 — ethyca-fides: upgrade to the fixed version with the command below.
pip install --upgrade 'ethyca-fides>=2.22.1'Details
### Impact
The Fides web application allows a custom integration to be uploaded as a ZIP file containing configuration and dataset definitions in YAML format.
It was discovered that specially crafted YAML dataset and config files allow a malicious user to perform arbitrary requests to internal systems and exfiltrate data outside the environment (also known as a Server-Side Request Forgery). The application does not perform proper validation to block attempts to connect to internal (including localhost) resources.
Exploitation is limited to API clients with the `CONNECTOR_TEMPLATE_REGISTER` authorization scope. In the Fides Admin UI this scope is restricted to highly privileged users, specifically root users and users with the owner role.
### Patches The vulnerability has been patched in Fides version `2.22.1`. Users are advised to upgrade to this version or later to secure their systems against this threat.
### Workarounds There are no workarounds.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ethyca/fides/security/advisories/GHSA-jq3w-9mgf-43m4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-46124[ADVISORY]
- https://github.com/ethyca/fides/commit/cd344d016b1441662a61d0759e7913e8228ed1ee[WEB]
- https://github.com/ethyca/fides[PACKAGE]
- https://github.com/ethyca/fides/releases/tag/2.22.1[WEB]
- https://pypi.org/project/ethyca-fides[PACKAGE]
- https://github.com/advisories/GHSA-jq3w-9mgf-43m4[ADVISORY]