ssrf

package
v3.99.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: AGPL-3.0 Imports: 5 Imported by: 0

Documentation

Overview

Package ssrf guards outbound connections whose destinations are taken from scanned or otherwise untrusted content (a secret's "domain"/"endpoint", a connection string, a URL in a config file). Without a guard, an attacker who can plant such content can steer an HTTP client at internal-only addresses, and redirects turn an attacker-owned endpoint into a pivot into internal space (cluster services, the cloud metadata server, etc.).

The check runs inside the dialer (via ControlContext), after DNS resolution and immediately before the socket connects. That placement matters for two reasons:

  • It is DNS-rebinding safe: a hostname that resolves to a public IP on a pre-flight check but to 169.254.169.254 at connect time is still caught, because the check runs on the address actually being dialed.
  • It covers HTTP redirects: any redirect hop that opens a new connection re-dials through the guarded dialer, and every fresh dial re-checks the resolved IP.

Caveat: the guard inspects the address the transport dials. If an HTTP forward proxy is configured (HTTP(S)_PROXY), the transport dials the proxy and the proxy makes the final connection, so egress policy must also be enforced at the proxy.

Index

Constants

This section is empty.

Variables

View Source
var ErrEgressBlocked = errors.New("egress blocked: non-public address")

ErrEgressBlocked is wrapped by every error this package returns when it refuses a connection. Callers can errors.Is against it to treat a blocked egress as an expected, benign outcome rather than a failure.

Functions

func CheckDialAddress

func CheckDialAddress(address string) error

CheckDialAddress rejects a dial target whose IP is not a public address. Every rejection wraps ErrEgressBlocked so callers can recognize it. The address must be a resolved "ip:port" pair as seen by a dialer Control hook; anything else is refused (fail closed).

func GuardDialer

func GuardDialer(base *net.Dialer) *net.Dialer

GuardDialer returns a copy of base (or a zero dialer when base is nil) that refuses non-public targets via CheckDialAddress. The check is installed as ControlContext because the net package ignores Control whenever ControlContext is set: installing the guard as Control would let a base dialer carrying a ControlContext bypass it entirely. Any ControlContext or Control already set on base runs after the check, for allowed targets only.

func IsNonPublicIP

func IsNonPublicIP(ip net.IP) bool

IsNonPublicIP reports whether an IP must not be dialed by a guarded client: loopback, link-local (incl. cloud metadata), private (RFC1918/RFC4193), CGNAT, multicast, unspecified, the special-use ranges above, and IPv6 embeddings of any of those.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL