Fix SSRF issue - #274
Fix SSRF issue#2740x1f wants to merge 7 commits into
Conversation
0x1f
commented
Jan 11, 2026
- Fixed the SSRF security vulnerability, preventing access to private networks and cloud metadata.
✅ Deploy Preview for web-check ready!Built without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify project configuration. |
…s during timeouts or network errors, leading to process crashes.
|
Conflicts have been resolved by merging upstream master. |
lissy93
left a comment
There was a problem hiding this comment.
Thanks @0x1f
But this seems counter-intuitive.
Web-check's entire purpose is to call a URL and show you what came back. That's SSRF by design. But there's literally no valid exploit path anywhere in the code, and every risk is already mitigated with the firewall config options. E.g. set API_BLOCKED_HOSTS to close of accessing of given domains, IPs or CIDR ranges, or just set publicOnlyChecks to prevent any private checks.
There was a problem hiding this comment.
I think this does the opposite of what you meant?
It will block harmless case, and then miss the actual attack, since it's only catching requests made by hostname, whereas attacker is going to use IP.
And I don't think it's wired up correctly to actually be being used, which is probably why the app was still working for you.