Skip to content

fix(network): recognise internal addresses written as trailing-dot na… - #15039

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
HouMinXi:fix/private-host-special-ranges
Sep 29, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
HouMinXi:fix/private-host-special-ranges

Conversation

@HouMinXi

@HouMinXi HouMinXi commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The outbound URL guard decides by the spelling of a host, and the same check
judges every DNS answer for a caller-supplied image URL. Several spellings of
internal targets got through: names with a trailing dot (localhost.,
metadata.google.internal.), IPv6 addresses that carry an IPv4 address (NAT64
64:ff9b::a9fe:a9fe, 6to4 2002:a9fe:a9fe::1, IPv4-compatible ::7f00:1),
the site-local and part of the link-local IPv6 ranges, multicast, 192.0.0.0/24
and the Azure host fabric address 168.63.129.16. A hostname whose DNS answer
was one of these addresses was fetched, and the metadata block in the
provider-validation mode let the metadata name and the NAT64 form of the
metadata address through.

Strip one trailing dot when normalising a host, read the IPv4 address out of
the mapped, compatible, NAT64 and 6to4 forms and judge that, cover the missing
IPv6 ranges by prefix length, and add the Azure address to the metadata list,
with 192.0.0.192, the secondary metadata address of Oracle Cloud, which sits
in the newly private 192.0.0.0/24 and so would otherwise be reachable in the
local-first mode that only blocks metadata. 198.18.0.0/15 stays allowed because
fake-IP proxy setups answer with it, and 240.0.0.0/4 stays as it was.

The AWS IPv6 metadata address is now compared as an address, so its longer
spellings are blocked too, and the parser reads the dotted tails and zone ids
that DNS answers and raw text can carry. The IPv4-mapped check in the upstream
proxy validator is folded onto the same parser, which leaves its own multicast
rule redundant, so that goes.

Related Issues

  • None. This fixes a defect found by review, not a filed issue.

Validation

  • Change type: other
  • Focused tests: tests/unit/private-host-special-ranges.test.ts
  • npm run lint
  • Reconciled with the current active release base
  • Production-code changes include a new or updated automated test in this PR

Tests Added Or Updated

  • tests/unit/private-host-special-ranges.test.ts

Coverage Notes

  • The change is covered by the test files listed above. No coverage drop is expected; the new tests exercise the paths this PR adds.

Reviewer Notes

  • Host classification now recognises trailing-dot names and the special internal ranges. A name that only looked public because of the trailing dot is treated as internal.

…mes and IPv6 embeddings

The outbound URL guard decides by the spelling of a host, and the same check
judges every DNS answer for a caller-supplied image URL. Several spellings of
internal targets got through: names with a trailing dot (`localhost.`,
`metadata.google.internal.`), IPv6 addresses that carry an IPv4 address (NAT64
`64:ff9b::a9fe:a9fe`, 6to4 `2002:a9fe:a9fe::1`, IPv4-compatible `::7f00:1`),
the site-local and part of the link-local IPv6 ranges, multicast, 192.0.0.0/24
and the Azure host fabric address 168.63.129.16. A hostname whose DNS answer
was one of these addresses was fetched, and the metadata block in the
provider-validation mode let the metadata name and the NAT64 form of the
metadata address through.

Strip one trailing dot when normalising a host, read the IPv4 address out of
the mapped, compatible, NAT64 and 6to4 forms and judge that, cover the missing
IPv6 ranges by prefix length, and add the Azure address to the metadata list,
with 192.0.0.192, the secondary metadata address of Oracle Cloud, which sits
in the newly private 192.0.0.0/24 and so would otherwise be reachable in the
local-first mode that only blocks metadata. 198.18.0.0/15 stays allowed because
fake-IP proxy setups answer with it, and 240.0.0.0/4 stays as it was.

The AWS IPv6 metadata address is now compared as an address, so its longer
spellings are blocked too, and the parser reads the dotted tails and zone ids
that DNS answers and raw text can carry. The IPv4-mapped check in the upstream
proxy validator is folded onto the same parser, which leaves its own multicast
rule redundant, so that goes.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@diegosouzapw
diegosouzapw merged commit 4673b43 into diegosouzapw:release/v3.8.51 Sep 29, 2026
9 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants