Fetch user-supplied URLs in Python without opening an SSRF hole. Stdlib only, no dependencies. - Rehanfaisal/ssrf-safe-fetch

1 points•rehandevv•5 days ago•1 comment•

1 comment

rehandevv5 days ago
This came out of building IsSiteSafe, where some tools fetch URLs that visitors submit. I used AI assistance while building the project, and extracted the fetching code into a small Python module.

It uses the standard library, checks resolved addresses before each request, and checks redirect destinations too.

An important limitation: it doesn’t pin the connection to the address it checked, so DNS rebinding is still possible. It also strips query strings, which makes it unsuitable for some URLs. I wouldn’t describe it as complete SSRF protection.

I’d appreciate feedback on those boundaries and on cases the current checks miss.

Read the full thread on Hacker News →

Related stories