fix: reject private IPs after DNS resolution (SSRF/DNS-rebinding)

The SSRF guard only checked the host string, so an attacker-owned domain
resolving to 169.254.169.254 / 10.x (DNS rebinding, TOCTOU) bypassed it.
Add a reqwest dns::Resolve (SafeResolver) that drops resolved addresses in
private ranges, wired into all four crawler/analysis clients — it fires per
connection so it also covers redirect hops. Also close the is_private_ip
IPv6-embedding gaps (IPv4-compatible ::/96, NAT64 64:ff9b::/96, 6to4
2002::/16 all now unwrap to the embedded IPv4).

Bump to 0.124.10.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-07 21:52:30 +02:00
parent 61669aac3f
commit ff4ca964f5
6 changed files with 155 additions and 10 deletions

View File

@@ -1,6 +1,6 @@
[package]
name = "mangalord"
version = "0.124.9"
version = "0.124.10"
edition = "2021"
default-run = "mangalord"