Skip to content

Provider Hub v0.6.11

Choose a tag to compare

@HeWhenJay HeWhenJay released this 17 Aug 09:23

SSRF hardening

  • Parses IPv6 addresses into normalized numeric segments before classification.
  • Detects compressed, expanded, and dotted IPv4-mapped IPv6 forms.
  • Converts mapped final 32 bits back to IPv4 and applies the complete non-public IPv4 policy.
  • Blocks loopback examples including ::ffff:7f00:1, 0:0:0:0:0:ffff:7f00:1, and ::ffff:127.0.0.1 before any HTTPS source request.
  • Retains the existing DNS+HTTPS end-to-end hard deadline and pinned-public-address request design.

Verification

  • 99/99 tests passed.
  • Added mapped and expanded IPv6 loopback source rejection regression coverage.
  • Package dry-run, syntax and diff checks passed.

SHA-256: 67578517FF813BC754EFA1A23070CAD48B918F8F0E3498848FD9BF340CD17D4E