Skip to main content

One post tagged with "ssrf"

View All Tags

Your Gateway Broke on v3.5.0: The Proxy Middleware's New SSRF Policy

ยท 22 min read
Fiber Team
Maintainers

You bump Fiber from v3.4.0 to v3.5.0, the tests pass, the deploy goes out, and every request to /api/users comes back as a 500. The body of that response tells anyone who asks exactly what went wrong:

proxy: upstream host resolves to a blocked address: localhost -> 127.0.0.1

In a Docker Compose or Kubernetes setup the hostname is users or users.default.svc and the IP starts with 10. or 172., but the message is the same. If the upstream in your proxy.Balancer config is an IP literal, you do not even get that far: the process panics at startup with proxy: upstream host resolves to a blocked address: 127.0.0.1.

This is not a regression. Fiber v3.5.0 hardened the proxy middleware (#4405), and its new default policy rejects upstreams on loopback, private, link-local and similar addresses. That default is right for code that forwards requests to URLs it did not choose, and inconvenient for the most common use of the middleware, an API gateway in front of internal services. This post shows how to give each kind of proxying the policy it needs, with one gateway that does both, built and tested against Fiber v3.5.0.