fix(bedrock_mantle): validate aws_region_name before URL construction

Prevents bearer-token exfiltration via a malicious region value injected
through a proxy request. The resolved region is now validated against the
existing _validate_aws_region_name regex (lowercase alphanumerics and
hyphens only) before it is interpolated into the endpoint URL.

Flagged by Veria AI on PR #29711.
This commit is contained in:
Jeremy McGee 2026-06-08 09:33:50 -04:00
parent 6edd986c80
commit 5155e7d029
2 changed files with 19 additions and 0 deletions

View file

@ -56,6 +56,7 @@ class BedrockMantleResponsesAPIConfig(OpenAIResponsesAPIConfig, BaseAWSLLM):
litellm_params: dict,
) -> str:
explicit_region = self._explicit_region(litellm_params.get("aws_region_name"))
self._validate_aws_region_name(explicit_region)
base = (
api_base
or get_secret_str("BEDROCK_MANTLE_API_BASE")

View file

@ -138,6 +138,24 @@ class TestBedrockMantleResponsesURL:
url = cfg.get_complete_url(api_base=None, litellm_params={})
assert url == "https://bedrock-mantle.us-east-2.api.aws/openai/v1/responses"
@pytest.mark.parametrize(
"malicious_region",
[
"us-east-2.attacker.com/",
"us-east-2.evil.com",
"foo/bar",
"us-east-1;rm -rf /",
"UPPER-CASE",
],
)
def test_url_rejects_malicious_region(self, clear_aws_env, malicious_region):
cfg = BedrockMantleResponsesAPIConfig()
with pytest.raises(ValueError, match="Invalid AWS region format"):
cfg.get_complete_url(
api_base=None,
litellm_params={"aws_region_name": malicious_region},
)
class TestBedrockMantleResponsesAuth:
def test_config_api_key_takes_priority(self, monkeypatch):