diff --git a/litellm/proxy/auth/auth_utils.py b/litellm/proxy/auth/auth_utils.py index d71de181977..91c8f2dd7c9 100644 --- a/litellm/proxy/auth/auth_utils.py +++ b/litellm/proxy/auth/auth_utils.py @@ -195,6 +195,14 @@ def is_request_body_safe( "posthog_host", "braintrust_host", "slack_webhook_url", + # Provider-specific endpoint overrides that flow into the outbound + # request via ``optional_params``. Same threat as ``api_base``: + # ``s3_endpoint_url`` redirects Bedrock file uploads to attacker + # S3; ``sagemaker_base_url`` redirects all SageMaker traffic; + # ``deployment_url`` redirects SAP deployments. + "s3_endpoint_url", + "sagemaker_base_url", + "deployment_url", ] # The blocklist is enforced unconditionally. Legitimate clientside diff --git a/tests/test_litellm/proxy/auth/test_auth_utils.py b/tests/test_litellm/proxy/auth/test_auth_utils.py index 222787e9ea2..91f300b88ce 100644 --- a/tests/test_litellm/proxy/auth/test_auth_utils.py +++ b/tests/test_litellm/proxy/auth/test_auth_utils.py @@ -912,6 +912,9 @@ class TestIsRequestBodySafeBlocksEndpointTargetingFields: "posthog_host", "braintrust_host", "slack_webhook_url", + "s3_endpoint_url", + "sagemaker_base_url", + "deployment_url", ], ) def test_endpoint_targeting_field_in_request_body_is_rejected(self, field):