Skip to content

fix: harden HTTP resource fetching against SSRF - #109

Merged
starboyate merged 1 commit into
mainfrom
fix-http-resource-fetcher-ssrf
May 29, 2026
Merged

starboyate merged 1 commit into
mainfrom
fix-http-resource-fetcher-ssrf

Conversation

@starboyate

Copy link
Copy Markdown
Collaborator

Summary

  • Add a secure default HTTP resource fetch policy that validates schemes, hosts, userinfo, and resolved addresses before any outbound request.
  • Disable automatic HttpClient redirects and follow redirects manually so each redirect target is revalidated, with redirect-count enforcement and HTTPS-to-HTTP downgrade rejection.
  • Add an explicit private-network opt-in while keeping loopback, link-local, multicast, and special-use ranges blocked, and document sourceUrl as untrusted.

Fixes #100

Compatibility

  • Custom HttpClient instances passed to HttpResourceFetcher must use HttpClient.Redirect.NEVER; clients with automatic redirects are rejected so redirect targets can be validated safely.

Test Plan

  • mvn -pl memind-core -Dtest=HttpResourceFetcherTest,HttpResourceFetchPolicyTest test
  • mvn -pl memind-core test
  • mvn -pl memind-core spotless:check checkstyle:check

@starboyate
starboyate merged commit b540940 into main May 29, 2026
2 checks passed
@starboyate
starboyate deleted the fix-http-resource-fetcher-ssrf branch June 5, 2026 06:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant