Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability in the safeurl library allows an attacker to bypass configured restrictions on accessing internal network destinations by manipulating how URLs are formatted. While the library is intended to enhance security by validating URLs, a flaw in its handling of IPv4 and IPv6 addresses means that certain destinations, even if blocked, can still be reached.
- A flaw lets blocked internal network addresses be reached.
- This could expose internal systems if the library is used.
- Assess if your use of this library is affected.
Attack Path
How an attacker could exploit the issue
An attacker could leverage this Server-Side Request Forgery vulnerability if they can control a URL that is processed by the safeurl library. By manipulating the format of the URL, particularly by using IPv6 addressing or hostnames that resolve to non-IPv4 addresses, an attacker could bypass the library's intended restrictions and cause the application to send requests to internal network destinations. This bypass is possible because the library's validation logic only correctly checks IPv4 addresses against reserved ranges and blocklists.
- No authentication or privileges needed.
- Attacker crafts a URL to bypass restrictions.
- Unauthorized access to internal network resources.
Live Threat
Current exploitation, exposure, and threat context
A Server-Side Request Forgery vulnerability in the Slab safeurl library could allow an attacker to bypass configured blocklists and access internal network destinations when certain URL formats are used and the library is not configured with an allowlist. This occurs because only IPv4 addresses are matched against reserved ranges and blocklists, while other address formats, including IPv6 or hosts resolving to no IPv4 address, may be accepted.
- Internal network destinations.
- Validated URLs reach internal destinations.
- Unauthorized network access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This Server-Side Request Forgery (SSRF) vulnerability requires action from teams responsible for applications that use the `safeurl` library. The first practical step is to identify all instances of this library, confirm if they are business-critical or reachable, and then determine the accountable owner for remediation planning.
- Application owners should be responsible.
- Verify application reachability and criticality.
- Plan remediation based on identified risk.