The SSRF guard evaluates the initial URL's canonical host (#3940), but upstream HttpExtendsFetcher follows redirects internally with no hook, so a redirect off the allowlist and hostname-based targets (localhost aliases, *.nip.io, DNS rebinding) are unchecked. Mitigation today is max_manifest_url_redirects = 0. Tracked upstream in responsibleai/agent-control-spec#20.
Found in the group review of the policy-engine retarget (#3939) and deferred from the follow-up (#3940).
The SSRF guard evaluates the initial URL's canonical host (#3940), but upstream HttpExtendsFetcher follows redirects internally with no hook, so a redirect off the allowlist and hostname-based targets (localhost aliases, *.nip.io, DNS rebinding) are unchecked. Mitigation today is max_manifest_url_redirects = 0. Tracked upstream in responsibleai/agent-control-spec#20.
Found in the group review of the policy-engine retarget (#3939) and deferred from the follow-up (#3940).