Root cause
Authentication & access control introduced
The URL check tests literal IP addresses and treats a hostname parsing failure as a non-IP name.
How AI contributed
Direct introductionProvisional finding. Full causal and release verification remains incomplete.
Root cause
The URL check tests literal IP addresses and treats a hostname parsing failure as a non-IP name.
Fix
The replacement checks resolved addresses and blocks a hostname when DNS resolution fails.
@@ -30,0 +55,18 @@+ if hostname in ['localhost', '127.0.0.1', '0.0.0.0', '::1']:+ return False+ + # Block private IP ranges+ import ipaddress+ try:+ ip = ipaddress.ip_address(hostname)+ if ip.is_private or ip.is_reserved or ip.is_loopback or ip.is_link_local:+ return False+ except ValueError:+ # Not an IP address, continue with domain validation+ pass+ + # Block common internal domains+ if any(hostname.endswith(domain) for domain in ['.local', '.internal', '.localdomain']):+ return False+ + # Block metadata service endpoints@@ -58,11 +58,13 @@ pass try:- return _ip_blocked(ipaddress.ip_address(socket.inet_aton(host)))- except OSError:- pass+ for info in socket.getaddrinfo(host, None):+ if _ip_blocked(ipaddress.ip_address(info[4][0])):+ return True+ except socket.gaierror:+ return True return False class SpiderTools: """Tools for web scraping and crawling."""AI-assisted change 6aa9e4c3c210fc441a5c0b2825aa5d6d766f0003248f41822fa185429b60d45d · Fix 85bea1a37061ebdc603628c81cdcd4312e1ef0e759fd79586217705b3df5556d
Advisory references