Gemini CLI fixes SSRF vulnerability with enhanced DNS validation and SNI preservation
diegogodinezr · ghdev · 2026-08-29
This PR enhances security in WebFetchTool by improving destination address validation and connection routing. Key changes include asynchronous DNS resolution with validation of all returned IPs, filtering private or reserved ranges (e.g., RFC 1918, loopback), and implementing transport layer connection pinning via Undici to bind directly to resolved IPs. It preserves TLS SNI to ensure proper HTTPS handshakes and adopts a fail-closed approach to prevent DNS rebinding or SSRF attacks.
More from Infra
- First vLLM Conference wraps with a capacity rooftop happy hour co-hosted by AMD — vllm_project · 2026-08-29
- AtomicChat's Qwen3.8-Flash-Next Quant Cuts RAM from 106GB to 65GB, Prefill at 500 t/s — tolitius · 2026-08-29
- Cerebras founder: AI is accelerating hardware evolution and reshaping the industry — Sethwinterroth · 2026-08-29
- Debating between Apple M5 Ultra and RTX 6000 Pro for image/video model inference — Bulky_Astronomer7264 · 2026-08-29
- MCP usage explodes as Agent Handler calls surge 1220x this year — shensi · 2026-08-29
- MiniMax optimizes prompt expansion latency to under 1.5s — isidentical · 2026-08-29