Our SSRF guard passed every test we ran — until a stranger's comment pointed out the test we never ran
This story is from 2026-09-14. It is preserved in the archive; the latest stories are on the live feed.
Three weeks ago, in the comments under a post about a different SSRF bug (CVE-2026-19304, a parser-confusion issue), someone asked a sharp question about our own URL-fetching endpoints. I answered honestly that we'd only tested that our hostname-validation and the actual fetch agreed on parsing the…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-14 19:26 · DEV Community — AI
Our SSRF guard passed every test we ran — until a stranger's comment pointed out the test we never ran
More stories
- Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks — Bloomberg AI
- Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
- Introducing Amazon SageMaker HyperPod Inference Gateway — AWS Machine Learning Blog
- Introducing Astra for Law — OpenAI News
- Newsom signs executive order to explore new AI rules, consider ‘kill switch’ — Politico Technology
- Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
- Sources: Anthropic considers releasing a new AI model to counter OpenAI's momentum since Astra's launch, ahead of an IPO and after Amodei's call for a slowdown (Reuters) — Techmeme
- Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
Get the daily brief of stories like this at 6:30 every morning →