Fetch user-supplied URLs in Python without opening an SSRF hole. Stdlib only, no dependencies. - Rehanfaisal/ssrf-safe-fetch
1 comment
rehandevv5 days ago
This came out of building IsSiteSafe, where some tools fetch URLs that visitors submit. I used AI assistance while building the project, and extracted the fetching code into a small Python module.
It uses the standard library, checks resolved addresses before each request, and checks redirect destinations too.
An important limitation: it doesn’t pin the connection to the address it checked, so DNS rebinding is still possible. It also strips query strings, which makes it unsuitable for some URLs. I wouldn’t describe it as complete SSRF protection.
I’d appreciate feedback on those boundaries and on cases the current checks miss.
Read the full thread on Hacker News →
Related stories
- Hacker News · 2 points · about 11 hours ago
- Lobsters · 22 points · about 10 years ago
- Lobsters · 10 points · 6 months ago
- yieldfrom 1.0.0: A backport of the `yield from` semantic from Python 3.x to Python 2.7pypi.python.orgLobsters · 11 points · over 9 years ago
- Jubilant: Python subprocess and Go codegenbenhoyt.comLobsters · 14 points · 10 months ago
- DEV Community · 13 points · 7 days ago