Repository navigation
fix(network): recognise internal addresses written as trailing-dot na… - #15039
Merged
diegosouzapw merged 1 commit intoSep 29, 2026
Merged
diegosouzapw merged 1 commit into
diegosouzapw merged 1 commit into
Conversation
…mes and IPv6 embeddings The outbound URL guard decides by the spelling of a host, and the same check judges every DNS answer for a caller-supplied image URL. Several spellings of internal targets got through: names with a trailing dot (`localhost.`, `metadata.google.internal.`), IPv6 addresses that carry an IPv4 address (NAT64 `64:ff9b::a9fe:a9fe`, 6to4 `2002:a9fe:a9fe::1`, IPv4-compatible `::7f00:1`), the site-local and part of the link-local IPv6 ranges, multicast, 192.0.0.0/24 and the Azure host fabric address 168.63.129.16. A hostname whose DNS answer was one of these addresses was fetched, and the metadata block in the provider-validation mode let the metadata name and the NAT64 form of the metadata address through. Strip one trailing dot when normalising a host, read the IPv4 address out of the mapped, compatible, NAT64 and 6to4 forms and judge that, cover the missing IPv6 ranges by prefix length, and add the Azure address to the metadata list, with 192.0.0.192, the secondary metadata address of Oracle Cloud, which sits in the newly private 192.0.0.0/24 and so would otherwise be reachable in the local-first mode that only blocks metadata. 198.18.0.0/15 stays allowed because fake-IP proxy setups answer with it, and 240.0.0.0/4 stays as it was. The AWS IPv6 metadata address is now compared as an address, so its longer spellings are blocked too, and the parser reads the dotted tails and zone ids that DNS answers and raw text can carry. The IPv4-mapped check in the upstream proxy validator is folded onto the same parser, which leaves its own multicast rule redundant, so that goes. Signed-off-by: Minxi Hou <houminxi@gmail.com>
diegosouzapw
merged commit Sep 29, 2026
4673b43
into
diegosouzapw:release/v3.8.51
9 of 16 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The outbound URL guard decides by the spelling of a host, and the same check
judges every DNS answer for a caller-supplied image URL. Several spellings of
internal targets got through: names with a trailing dot (
localhost.,metadata.google.internal.), IPv6 addresses that carry an IPv4 address (NAT6464:ff9b::a9fe:a9fe, 6to42002:a9fe:a9fe::1, IPv4-compatible::7f00:1),the site-local and part of the link-local IPv6 ranges, multicast, 192.0.0.0/24
and the Azure host fabric address 168.63.129.16. A hostname whose DNS answer
was one of these addresses was fetched, and the metadata block in the
provider-validation mode let the metadata name and the NAT64 form of the
metadata address through.
Strip one trailing dot when normalising a host, read the IPv4 address out of
the mapped, compatible, NAT64 and 6to4 forms and judge that, cover the missing
IPv6 ranges by prefix length, and add the Azure address to the metadata list,
with 192.0.0.192, the secondary metadata address of Oracle Cloud, which sits
in the newly private 192.0.0.0/24 and so would otherwise be reachable in the
local-first mode that only blocks metadata. 198.18.0.0/15 stays allowed because
fake-IP proxy setups answer with it, and 240.0.0.0/4 stays as it was.
The AWS IPv6 metadata address is now compared as an address, so its longer
spellings are blocked too, and the parser reads the dotted tails and zone ids
that DNS answers and raw text can carry. The IPv4-mapped check in the upstream
proxy validator is folded onto the same parser, which leaves its own multicast
rule redundant, so that goes.
Related Issues
Validation
tests/unit/private-host-special-ranges.test.tsnpm run lintTests Added Or Updated
tests/unit/private-host-special-ranges.test.tsCoverage Notes
Reviewer Notes