Skip to content

[Aikido] Prevent redirect-based SSRF attacks in PHP stream wrappers via domain allowlisting - #511

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137917539-954r
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137917539-954r

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This patch mitigates redirect-based SSRF (Server-Side Request Forgery) attacks in PHP stream wrapper functions (file_get_contents, fopen, file) by implementing domain allowlisting validation. The fix prevents attackers from exploiting HTTP redirects to reach internal addresses that cannot be detected after the request completes. Changes were made to lib/request-processor/handle_urls.go to document the new protection and lib/request-processor/vulnerabilities/ssrf/checkDomainAllowlist.go to implement the allowlist validation logic that blocks requests to non-allowlisted domains when URLs are user-controlled.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811697379
HIGH
HTTP(S) path arguments are recorded for pre-request SSRF validation, then the original PHP stream operation executes before the post hook. The post hook assigns outgoingRequestEffectiveUrl from outgoingRequestUrl because it cannot obtain the URL reached after redirects, and it does not provide the connected/resolved IP. Consequently, a public URL that redirects to an internal destination is represented to the downstream validator as an unchanged public request. Because the stream operation has already followed the redirect, the redirected response can be returned to PHP application code before post-processing can prevent the request.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant