Executive brief
SafeURL-Python is a library designed to prevent Server-Side Request Forgery (SSRF) attacks by blocking requests to internal and private IP addresses. The library's hostname blocklist can be bypassed by adding a trailing dot to convert a hostname into a Fully Qualified Domain Name (FQDN), allowing attackers to circumvent custom hostname restrictions set by developers.
Technical details
The vulnerability is a hostname matching bypass in SafeURL-Python's blocklist validation logic. When a hostname is blacklisted, an attacker can bypass the check by appending a trailing dot (e.g., "example.com" becomes "example.com."), which converts the hostname to FQDN format that the regex or string comparison fails to match. The vulnerability requires the application to have explicitly configured custom hostname blocklists; the library's built-in protections against internal/private IP addresses are not affected. This enables SSRF attacks against specifically-blocked internal services. The vulnerability was patched in version 1.3 via pull request #6.
Affected products
- IncludeSecurity SafeURL-Python <1.3
Timeline
- 2023-06-29: disclosed
- 2023-06-23: patched: Fix merged in pull request #6