#99 FTX-99: WEBHOOK_ALLOW_HOSTS is inert for bare hosts — allowlist only matches host:port entries

closed high bug Created 2026-07-31 18:15 · Updated 2026-07-31 18:19

Description

Edit
EARS SPEC: - Where a host is listed in WEBHOOK_ALLOW_HOSTS without a port, the Futex SSRF guard shall exempt that host on any port. - Where a host is listed with an explicit port, the Futex SSRF guard shall exempt that host only on that port. - If a host is not listed in WEBHOOK_ALLOW_HOSTS and resolves to a blocked address, then the Futex SSRF guard shall reject the URL. CAUSE: app/security/net_guard.py _is_allowlisted() iterates the allowlist but its only match branch is guarded by 'if ":" in entry'. A bare host entry can never match, so the allowlist silently does nothing. BLAST RADIUS: production runs WEBHOOK_ALLOW_HOSTS=127.0.0.1,localhost (both bare), so the exemption intended for internal webhook consumers has never worked — every loopback webhook target is rejected with 422. Pre-existing since commit 5195837; found because tests/e2e/test_full_flow.py fails on it. This is a config that looks correct and is inert.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...