You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Remediates a high-severity SSRF vulnerability (CWE-918) in the HTTP
source implementation.
- Implemented `SSRFGuard` to prevent DNS rebinding (TOCTOU) attacks.
- Added `allowPrivateNetworks`, `allowedIpRanges`, and
`customBlockedIpRanges` properties to configure boundary safety.
- Implemented early fast-fail validation on the configured `BaseURL` at
initialization time.
- Emits an explicit warning detail highlighting the Man-in-the-Middle
(MITM) risk when `disableSslVerification` is enabled.
Reported by: Syed Anas Mohiuddin
Copy file name to clipboardExpand all lines: docs/en/integrations/http/source.md
+21Lines changed: 21 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -54,5 +54,26 @@ instead of hardcoding your secrets into the configuration file.
54
54
| queryParams | map[string]string | false | Default query parameters to include in the HTTP requests. |
55
55
| returnFullError | bool | false | Include raw upstream response bodies in error messages for non-2xx responses. Defaults to `false`. |
56
56
| disableSslVerification | bool | false | Disable SSL certificate verification. This should only be used for local development. Defaults to `false`. |
57
+
| allowPrivateNetworks | bool | false | Allow requests and redirects to loopback and private networks (RFC 1918 / link-local). Defaults to `false`. |
58
+
| allowedIpRanges |[]string | false | List of IP addresses or CIDR blocks to explicitly allow (whitelisted overrides). |
59
+
| customBlockedIpRanges |[]string | false | List of IP addresses or CIDR blocks to explicitly block. |
60
+
61
+
## Advanced Usage
62
+
63
+
### SSRF Protection (SSRF Guard)
64
+
By default, the HTTP source implements strict protection against Server-Side Request Forgery (SSRF) and DNS Rebinding (TOCTOU) attacks. It automatically intercepts, resolves, and blocks connection requests to private IP ranges, loopback ranges (such as `127.0.0.1`), and link-local ranges (e.g. AWS/GCP metadata service at `169.254.169.254`).
65
+
66
+
To override the default protection or block custom ranges, configure `allowPrivateNetworks`, `allowedIpRanges`, and `customBlockedIpRanges`:
67
+
68
+
```yaml
69
+
kind: source
70
+
name: my-http-source
71
+
type: http
72
+
baseUrl: https://internal.corp/api
73
+
allowedIpRanges:
74
+
- 10.0.0.0/24 # Explicitly trust internal subnet
75
+
customBlockedIpRanges:
76
+
- 10.0.0.99 # Block a specific sensitive host inside the subnet
logger.WarnContext(ctx, "Insecure HTTP is enabled for HTTP source %s. TLS certificate verification is skipped.\n", r.Name)
87
-
}
88
-
89
-
client:= http.Client{
90
-
Timeout: duration,
91
-
Transport: tr,
97
+
logger.WarnContext(ctx, "WARNING: TLS certificate verification is skipped (InsecureSkipVerify: true) for HTTP source %s. This exposes all traffic for this source to Man-in-the-Middle (MITM) attacks. Do not use in production.", r.Name)
92
98
}
93
99
94
100
// Validate BaseURL
95
-
_, err=url.ParseRequestURI(r.BaseURL)
101
+
parsedURL, err:=url.ParseRequestURI(r.BaseURL)
96
102
iferr!=nil {
97
103
returnnil, fmt.Errorf("failed to parse BaseUrl %v", err)
0 commit comments