HF RL Explorer

SSRF protection bypass via DNS rebinding (TOCTOU) and missing allow‑list configuration

SSRF protection bypass via DNS rebinding (TOCTOU) and missing allow‑list configuration: a task in LegoFlow-SWE (Harbor dataset). Additionally, there is no way for administrators to explicitly allow specific internal addresses or CIDR ranges that legitimate IoT devices on private networks need to…

The task

Additionally, there is no way for administrators to explicitly allow specific internal addresses or CIDR ranges that legitimate IoT devices on private networks need to access. Without an allow‑list, enabling SSRF protection blocks all private ranges, breaking valid use cases.

Part of Lego-X/LegoFlow-SWE.