Skip to content

policy-engine: manifest_from_url does not re-validate redirect hops or hostnames #3948

Description

@MohammadHaroonAbuomar

The SSRF guard evaluates the initial URL's canonical host (#3940), but upstream HttpExtendsFetcher follows redirects internally with no hook, so a redirect off the allowlist and hostname-based targets (localhost aliases, *.nip.io, DNS rebinding) are unchecked. Mitigation today is max_manifest_url_redirects = 0. Tracked upstream in responsibleai/agent-control-spec#20.

Found in the group review of the policy-engine retarget (#3939) and deferred from the follow-up (#3940).

Activity

  1. added a commit that references this issue on Sep 21, 2026
    c1224cd
  2. added a commit that references this issue on Oct 1, 2026
    526ef6c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions