fix(security): close SSRF guard bypasses in ssrfGuard.js (#3714)
Closes four SSRF guard bypasses reported in #3714: - Block alternate IPv6 encodings (hex format, NAT64, IPv4-compatible, IPv4-mapped) by parsing to 16-bit groups - Normalize trailing dots on hostnames to prevent FQDN bypasses - Add assertPublicUrlResolved() with DNS resolution to block wildcard DNS domains resolving to private/metadata IPs - Add fetchPublic() to safely handle and validate HTTP redirects
This commit is contained in:
@@ -44,7 +44,7 @@ vi.mock("@/sse/utils/logger.js", () => ({
|
||||
}));
|
||||
|
||||
vi.mock("@/shared/utils/ssrfGuard.js", () => ({
|
||||
assertPublicUrl: vi.fn(),
|
||||
assertPublicUrlResolved: vi.fn(async () => {}),
|
||||
}));
|
||||
|
||||
import { handleFetch } from "@/sse/handlers/fetch.js";
|
||||
|
||||
Reference in New Issue
Block a user