Refuse [::], 0.0.0.0, IPv6 multicast and documentation space (closes #341)
check / check (push) Successful in 3m20s

On Linux a connection to the unspecified address [::] or 0.0.0.0
reaches the host's own loopback, and the SSRF guard let [::] through.
Both unspecified addresses now sit in alwaysBlockedNetworks, so an
allowlist reaches loopback only by naming it; ::/128 joins the default
blocklist beside 0.0.0.0/8. IPv6 multicast (ff00::/8) and documentation
space (2001:db8::/32) are refused by default. Every default blocklist
entry gets a one-line comment, and the README, the rules above each
list and the two pinning tests follow.

Model: opus-5-5
This commit is contained in:
2026-10-02 07:14:58 +00:00
parent eb4c4cc849
commit aadbab8cf0
6 changed files with 143 additions and 47 deletions
+5 -4
View File
@@ -1569,10 +1569,11 @@ func (h *Handlers) validateTargetURL(
msg := "Invalid target URL: " + err.Error()
// Only a private or reserved address's refusal says how
// to allow it. Metadata refusals never do: link-local and
// the other unconditional metadata addresses cannot be
// opened, and the default blocklist's public addresses,
// which listing does open, hand out credentials.
// to allow it. Other refusals never do: link-local, the
// unspecified addresses and the other unconditional
// metadata addresses cannot be opened, and the default
// blocklist's public addresses, which listing does open,
// hand out credentials.
if errors.Is(err, delivery.ErrBlockedPrivateOrReservedIP) {
msg += ". Private and reserved addresses are refused " +
"by default; the server's ALLOWED_EGRESS_CIDRS " +