fix(security): resolve IPv4 signed 32-bit integer overflow in SSRF pr…#3199
Conversation
GSSoC Label Checklist 🏷️@Priyanshu-byte-coder — please apply the appropriate labels before merging: Difficulty (pick one):
Quality (optional):
Validation (required to score):
|
… and pnpm version from 11 to 9
|
Closing this. Three problems: (1) the stated fix — IPv4 signed-32-bit overflow — isn't a real bug: the existing |
Summary
Resolves a critical Server-Side Request Forgery (SSRF) bypass by fixing a signed 32-bit integer overflow in the IP parsing logic.
Closes #3118
Type of Change
What Changed
ipToNumberutility insrc/lib/ssrf-protection.tsto construct IP numbers using safe unsigned multiplication (or>>> 0) instead of signed bitwise shifting.192.168.x.xand172.16.x.xfrom wrapping into negative numbers, ensuring they are properly detected and blocked by the private IP range checks.How to Test
192.168.1.1to theisPrivateIPcheck (or attempt to configure a webhook pointing to that IP).isPrivateIPreturnstrue).172.16.0.1and verify it is also blocked.Expected result: The vulnerability is patched and requests to internal network services are properly blocked.
Screenshots / Recordings
(Not applicable for this backend security fix)