The isBlockedIP SSRF guard in Dozzle's webhook notification dispatcher blocks loopback, link-local, multicast, and unspecified addresses but does not recognize IPv6 transition mechanism addresses (RFC 3056 6to4, RFC 6052 NAT64, RFC 4380 Teredo) that embed arbitrary IPv4 addresses. An authenticated user can bypass the guard to reach loopback services, cloud metadata endpoints (169.254.169.254), and other blocked ranges via webhook notification URLs.
github.com/amir20/dozzleb9df313)internal/notification/dispatcher/webhook.gointernal/notification/dispatcher/webhook.go:32-51:
func isBlockedIP(ip net.IP) bool {
if ip.IsLoopback() ||
ip.IsLinkLocalUnicast() ||
ip.IsLinkLocalMulticast() ||
ip.IsMulticast() ||
ip.IsInterfaceLocalMulticast() ||
ip.IsUnspecified() {
return true
}
if v4 := ip.To4(); v4 != nil && zeroNetV4.Contains(v4) {
return true
}
if ip.Equal(net.IPv4bcast) {
return true
}
return false
}
The guard intentionally allows RFC 1918 private ranges for self-hosted webhook targets, but blocks loopback (127.0.0.0/8, ::1), link-local (169.254.0.0/16, fe80::/10), and other non-routable addresses. IPv6 transition mechanism addresses bypass all these checks:
| Mechanism | Prefix | Embeds | isBlockedIP result |
|---|---|---|---|
| 6to4 | 2002::/16 |
any IPv4 in bits 16-47 | false |
| NAT64 WKP | 64:ff9b::/96 |
any IPv4 in bits 96-127 | false |
| Teredo | 2001:0000::/32 |
any IPv4 in bits 96-127 | false |
The safeDialContext function (line 53) resolves hostnames and checks each IP against isBlockedIP before establishing a TCP connection. This is used as the DialContext for the webhook HTTP client (line 115).
Webhook URLs are configured by authenticated Dozzle users through the notification settings UI. The guard exists to prevent authenticated users from using webhook delivery as a proxy to reach the host machine's loopback services or cloud metadata endpoint.
http://[2002:7f00:0001::1]:8080/ (6to4 embedding 127.0.0.1)safeDialContext2002:7f00:0001::1 is checked against isBlockedIP -- all predicates return falseAn authenticated user can bypass the SSRF guard to:
2002:a9fe:a9fe::1 (6to4) to steal instance credentials64:ff9b::7f00:1 (NAT64) or 2002:7f00:0001::1 (6to4)Note: RFC 1918 private ranges are intentionally allowed by the guard. This bypass specifically targets the blocked ranges (loopback and link-local/metadata) that the guard explicitly intends to prevent.
Bypass vectors:
# 6to4 embedding 127.0.0.1 (bypasses IsLoopback)
http://[2002:7f00:0001::1]:8080/
# NAT64 embedding 169.254.169.254 (bypasses IsLinkLocalUnicast)
http://[64:ff9b::a9fe:a9fe]/latest/meta-data/
# 6to4 embedding 169.254.169.254 (bypasses IsLinkLocalUnicast)
http://[2002:a9fe:a9fe::1]/latest/meta-data/
# Teredo embedding 127.0.0.1
http://[2001:0000:dead:beef:0000:0000:7f00:0001]:8080/
Verification that isBlockedIP returns false for all vectors:
package main
import (
"fmt"
"net"
)
func isBlockedIP(ip net.IP) bool {
return ip.IsLoopback() || ip.IsLinkLocalUnicast() || ip.IsLinkLocalMulticast() ||
ip.IsMulticast() || ip.IsInterfaceLocalMulticast() || ip.IsUnspecified()
}
func main() {
for _, v := range []string{
"2002:7f00:0001::1", // 6to4 -> 127.0.0.1
"64:ff9b::a9fe:a9fe", // NAT64 -> 169.254.169.254
"2002:a9fe:a9fe::1", // 6to4 -> 169.254.169.254
} {
ip := net.ParseIP(v)
fmt.Printf("%-35s blocked=%v\n", v, isBlockedIP(ip))
}
}
// Output: all false
Add IPv6 transition mechanism prefix checks to isBlockedIP:
func isBlockedIP(ip net.IP) bool {
// ... existing checks ...
// IPv6 transition mechanisms embedding arbitrary IPv4
if len(ip) == net.IPv6len {
if ip[0] == 0x20 && ip[1] == 0x02 { return true } // 6to4
if ip[0] == 0x00 && ip[1] == 0x64 && ip[2] == 0xff && ip[3] == 0x9b { return true } // NAT64
if ip[0] == 0x20 && ip[1] == 0x01 && ip[2] == 0x00 && ip[3] == 0x00 { return true } // Teredo
}
return false
}
Reported by tonghuaroot (tonghuaroot@gmail.com).
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-08T18:11:56Z",
"nvd_published_at": "2026-08-11T17:19:16Z",
"severity": "LOW"
}