Merge bugfix/url-guard-ssrf-bash32 into develop

This commit is contained in:
2026-09-15 21:42:56 -04:00
+8 -3
View File
@@ -41,9 +41,14 @@ _rest_charset_ok() ( LC_ALL=C; case "$1" in
# Literal local/private/metadata targets. This is a LITERAL check, not a DNS # Literal local/private/metadata targets. This is a LITERAL check, not a DNS
# one: it stops the obvious, not a hostname that resolves inward. # one: it stops the obvious, not a hostname that resolves inward.
_host_is_local() ( LC_ALL=C _host_is_local() ( LC_ALL=C
# ${1,,} not tr: no fork, and no SC2018/SC2019 noise. Safe because the # `nocasematch` not ${1,,}: the lowercase expansion is bash 4.0+, and macOS
# charset guard has already run — the string is [A-Za-z0-9.-] by here. # ships bash 3.2 as /bin/bash — there it raised "bad substitution" and the
case "${1,,}" in # subshell exited 1, i.e. "not local", so EVERY local/private/metadata host
# was allowed through. Keeps the no-fork property the lowercase form had.
# Safe because the charset guard has already run — the string is
# [A-Za-z0-9.-] by here, and LC_ALL=C keeps the folding ASCII-only.
shopt -s nocasematch
case "$1" in
localhost|*.localhost|*.local|0.0.0.0|broadcasthost) exit 0 ;; localhost|*.localhost|*.local|0.0.0.0|broadcasthost) exit 0 ;;
127.*|10.*|169.254.*|192.168.*) exit 0 ;; 127.*|10.*|169.254.*|192.168.*) exit 0 ;;
172.1[6-9].*|172.2[0-9].*|172.3[01].*) exit 0 ;; 172.1[6-9].*|172.2[0-9].*|172.3[01].*) exit 0 ;;