The `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked: - `64:ff9b:1::/48`: NAT64 local-use prefix (RFC 8215) - `5f00::/16`: Segment Routing (SRv6) SIDs (RFC 9602) - `3fff::/20`: documentation prefix (RFC 9637) - `100:0:0:1::/64`: Dummy IPv6 Prefix (RFC 9780) ### Impact If exploited, an attacker would potentially be able to reach resources hosted on the IPs residing in the missing ranges. ### Workarounds Disable IPv6 by setting `EnableIPv6(false)`. This is the default behavior of the library. ### Resolution Upgrade to v0.2.4 ### Credits safeurl thanks @tonghuaroot for reporting.
Update github.com/doyensec/safeurl to 0.2.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scansafeurl is Missing IPv6 CIDR Ranges in Blocklist affects github.com/doyensec/safeurl (go). Severity is medium. The `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked: - `64:ff9b:1::/48`: NAT64 local-use prefix (RFC 8215) - `5f00::/16`: Segment Routing (SRv6) SIDs (RFC 9602) - `3fff::/20`: documentation prefix (RFC 9637) - `100:0:0:1::/64`: Dummy IPv6 Prefix (RFC 9780) ### Impact If exploited, an attacker would potentially be able to reach resources hosted on the IPs residing in the missing ranges. ### Workarounds Disable IPv6 by setting `EnableIPv6(false)`. This is the default behavior of the library. ### Resolution Upgrade to v0.2.4 ### Credits safeurl thanks @tonghuaroot for reporting.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/doyensec/safeurl |
The `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked: - `64:ff9b:1::/48`: NAT64 local-use prefix (RFC 8215) - `5f00::/16`: Segment Routing (SRv6) SIDs (RFC 9602) - `3fff::/20`: documentation prefix (RFC 9637) - `100:0:0:1::/64`: Dummy IPv6 Prefix (RFC 9780) ### Impact If exploited, an attacker would potentially be able to reach resources hosted on the IPs residing in the missing ranges. ### Workarounds Disable IPv6 by setting `EnableIPv6(false)`. This is the default behavior of the library. ### Resolution Upgrade to v0.2.4 ### Credits safeurl thanks @tonghuaroot for reporting.
Update github.com/doyensec/safeurl to 0.2.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scansafeurl is Missing IPv6 CIDR Ranges in Blocklist affects github.com/doyensec/safeurl (go). Severity is medium. The `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked: - `64:ff9b:1::/48`: NAT64 local-use prefix (RFC 8215) - `5f00::/16`: Segment Routing (SRv6) SIDs (RFC 9602) - `3fff::/20`: documentation prefix (RFC 9637) - `100:0:0:1::/64`: Dummy IPv6 Prefix (RFC 9780) ### Impact If exploited, an attacker would potentially be able to reach resources hosted on the IPs residing in the missing ranges. ### Workarounds Disable IPv6 by setting `EnableIPv6(false)`. This is the default behavior of the library. ### Resolution Upgrade to v0.2.4 ### Credits safeurl thanks @tonghuaroot for reporting.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/doyensec/safeurl |
| <0.2.4 |
| 0.2.4 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <0.2.4 |
| 0.2.4 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard