1. Fix TOCTOU DNS rebinding bypass: _validate_url_for_ssrf now returns
the validated IP address. http_request rewrites the URL to connect
directly to the pinned IP (via _build_pinned_url) and sets the
original Host header, so httpx never re-resolves DNS independently.
2. Add missing IPv6 multicast range (ff00::/8) to _BLOCKED_NETWORKS
for parity with IPv4 multicast (224.0.0.0/4).
3. Fix test_blocks_unresolvable_host: mock now raises socket.gaierror
(the subclass caught by production code) instead of bare OSError.
4. Add tests for _build_pinned_url and IPv6 multicast blocking.
The `http_request`, `http_get`, and `http_post` primitives in the custom
code guardrail sandbox only validated URL syntax via `is_valid_url()`,
which merely checks for a scheme and netloc. This allowed guardrail code
to reach internal services and cloud metadata endpoints
(e.g. 169.254.169.254), leading to Server-Side Request Forgery (SSRF).
This commit adds `_validate_url_for_ssrf()` which:
- Blocks requests to all RFC 1918 private ranges (10/8, 172.16/12, 192.168/16)
- Blocks loopback (127/8, ::1), link-local (169.254/16, fe80::/10)
- Blocks cloud metadata endpoint 169.254.169.254
- Blocks carrier-grade NAT (100.64/10), multicast, broadcast, etc.
- Resolves hostnames via DNS and validates all resulting IPs to prevent
DNS rebinding attacks
- Blocks IPv4-mapped IPv6 addresses (::ffff:0:0/96)
Includes unit tests covering private IPs, metadata endpoints, IPv6
loopback, DNS rebinding scenarios, and public IP allowlisting.
Ref: #21259
Instead of returning a 400 error when return_to is passed without
control_plane_url configured, silently ignore it and proceed with
the normal same-origin SSO flow.
- Use openai/gpt-5 prefix to match existing doc conventions
- Clarify that additional_drop_params must be added to every affected
model entry, not just one
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
OpenCode sends a `reasoningSummary` Responses API param with chat
completion requests. Document how to use `additional_drop_params` to
drop it and avoid 400 errors from the OpenAI API.
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Add `if: github.repository == 'BerriAI/litellm'` guard to scheduled
jobs in stale.yml, codeql.yml, and create_daily_staging_branch.yml.
This matches the existing pattern in auto_update_price_and_context_window.yml
and prevents these workflows from running unnecessarily on fork repositories.
Verify that spend_logs_metadata is correctly merged into combined_metadata
and flows through to Prometheus custom labels. Tests cover: basic extraction,
precedence when keys overlap, all three metadata sources combined, and None
handling.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add spend_logs_metadata to combined_metadata in Prometheus logger so
custom metadata from x-litellm-spend-logs-metadata header can be used
in Prometheus custom labels.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Thread project_alias alongside project_id through the metadata pipeline so
callbacks receive the human-readable project name. DRY up duplicate metadata
dict construction in proxy_track_cost_callback and pass_through_endpoints by
reusing get_sanitized_user_information_from_key — future metadata fields only
need adding in one place.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>