3ef660098ab37a7950457da8ecc25b516e37ce4e

Author
Ayman Bagabas <ayman.bagabas@gmail.com>
Committer
Ayman Bagabas <ayman.bagabas@gmail.com>
Date

Message

fix(ssrf): handle DNS resolution in SSRF protection

Diff

 1diff --git a/pkg/ssrf/ssrf.go b/pkg/ssrf/ssrf.go
 2index 1ed96bd8f88c7005276e2d772161f3dbddf7c4a1..6a94d72e564c98698d8c43330f005b4ce253ec42 100644
 3--- a/pkg/ssrf/ssrf.go
 4+++ b/pkg/ssrf/ssrf.go
 5@@ -39,7 +39,14 @@ func NewSecureClient() *http.Client {
 6 
 7 				ip := net.ParseIP(host)
 8 				if ip == nil {
 9-					return nil, fmt.Errorf("unexpected non-IP address in dial: %s", host)
10+					ips, err := net.LookupIP(host) //nolint
11+					if err != nil {
12+						return nil, fmt.Errorf("DNS resolution failed for host %s: %v", host, err)
13+					}
14+					if len(ips) == 0 {
15+						return nil, fmt.Errorf("no IP addresses found for host: %s", host)
16+					}
17+					ip = ips[0] // Use the first resolved IP address
18 				}
19 				if isPrivateOrInternal(ip) {
20 					return nil, fmt.Errorf("%w", ErrPrivateIP)