An SSRF filter allowed a prefix that still maps inside
A callback you control is still the first proof that a server fetched a URL. A filter gap is the next note, and only when the program allows that hop. This card does not repeat the prefix.
- Original severity
- High (7.5) source-reported; not rescored by vulns.co
- Public source
- hackerone disclosure
- Program / vendor
- arkadiyt-projects
- Product / surface
- ssrf_filter library
- Weakness
- Server-side request forgery
- Affected boundary
- A server-side fetch that the filter treated as public
- Disclosure date
- 2026-03-31
- Public status checked
- 2026-09-28
- Public attribution
- tipsen
What the evidence established
The disclosed report says version 1.3.0 blocked one private-address range and missed a related prefix that can still route to an internal target. The maintainer merged a fix and the report was disclosed at High (7.5).
Why the impact was credible
The source reported that a filter meant to stop server-side requests to internal addresses could still be pointed at those addresses.
Durable engineering lesson
A callback you control is still the first proof that a server fetched a URL. A filter gap is the next note, and only when the program allows that hop. This card does not repeat the prefix.
Control pattern
Block every prefix that maps to an internal target, and test the filter against the address families you claim to deny.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-28.