cai/tests/tools/web
Mike German bb79146c68 fix(fetch_url): block cloud-metadata via IPv4-mapped IPv6 in SSRF guard
The fetch_url SSRF guard guarantees cloud-metadata endpoints (e.g.
169.254.169.254) are ALWAYS blocked, even when CAI_FETCH_ALLOW_INTERNAL
is set for an authorised internal pentest. That guarantee could be
bypassed with the IPv4-mapped IPv6 form of the IMDS address, e.g.
http://[::ffff:169.254.169.254]/ (or its hex form ::ffff:a9fe:a9fe),
because the metadata block is a plain string comparison against the bare
IPv4 literal. With allow_internal=True the private/reserved check is
skipped, so nothing caught the mapped form and the request reached IMDS.

Unwrap IPv4-mapped IPv6 addresses to their embedded IPv4 before the
metadata and private-range checks in both the literal-IP and DNS-resolved
paths. This also hardens the private-range check on Python versions that
do not classify mapped addresses as private/link-local.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Mike German <mike@stepsventures.com>
2026-07-06 21:31:06 -04:00
..
test_fetch_url.py fix(fetch_url): block cloud-metadata via IPv4-mapped IPv6 in SSRF guard 2026-07-06 21:31:06 -04:00