fix(06-13): full IANA special-use SSRF tables and reject zoned dial targets
This commit is contained in:
@@ -155,6 +155,9 @@ func dialControl(policy Policy) func(network, address string, c syscall.RawConn)
|
||||
if err != nil {
|
||||
return fmt.Errorf("fetchguard: unparseable dial address %q: %w", host, err)
|
||||
}
|
||||
if addr.Zone() != "" {
|
||||
return errPrivateIP
|
||||
}
|
||||
addr = addr.Unmap()
|
||||
if isReservedOrPrivate(addr) {
|
||||
return errPrivateIP
|
||||
|
||||
Reference in New Issue
Block a user