
🚨 HIGH - Ruby css_parser SSRF via @import remote fetch and redirect-to-file read (CVE-2026-53727) Ruby gem css_parser is vulnerable to server-side request forgery in CssParser::Parser#read_remote_file and related code paths that automatically follow @import URLs without adequate scheme or network-range filtering. The root cause is improper input validation and unsafe URL/redirect handling that allows access to private, loopback, and link-local targets and can be coerced into file:// via redirects. An attacker exploits this by supplying crafted CSS (or a URL to attacker-controlled CSS) that the application parses, causing the server to make outbound requests and follow redirect hops under the app’s network identity without needing elevated privileges beyond reaching the CSS processing path. Impact includes SSRF for internal service discovery/access and potential local file reads leading to sensitive data exposure when parsed/serialized by downstream consumers (e.g., Premailer output). 👉 Affected: css_parser < 3.0.0 | Upgrade to 3.0.0
Post summary
CVE‑2026‑53727 exposes SSRF and potential local file read in the Ruby css_parser gem via @import handling; upgrading to version 3.0.0 mitigates the issue.
