vulns.co
/
GKData.io MCP

Back to Reports

An SSRF filter allowed a prefix that still maps inside

A callback you control is still the first proof that a server fetched a URL. A filter gap is the next note, and only when the program allows that hop. This card does not repeat the prefix.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
High (7.5) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
arkadiyt-projects
Product / surface
ssrf_filter library
Weakness
Server-side request forgery
Affected boundary
A server-side fetch that the filter treated as public
Disclosure date
2026-03-31
Public status checked
2026-09-28
Public attribution
tipsen

What the evidence established

The disclosed report says version 1.3.0 blocked one private-address range and missed a related prefix that can still route to an internal target. The maintainer merged a fix and the report was disclosed at High (7.5).

Why the impact was credible

The source reported that a filter meant to stop server-side requests to internal addresses could still be pointed at those addresses.

Durable engineering lesson

A callback you control is still the first proof that a server fetched a URL. A filter gap is the next note, and only when the program allows that hop. This card does not repeat the prefix.

Control pattern

Block every prefix that maps to an internal target, and test the filter against the address families you claim to deny.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.