Meziantou.Framework.Http.ServerSideRequestForgery
1.0.0
Prefix Reserved
dotnet add package Meziantou.Framework.Http.ServerSideRequestForgery --version 1.0.0
NuGet\Install-Package Meziantou.Framework.Http.ServerSideRequestForgery -Version 1.0.0
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Meziantou.Framework.Http.ServerSideRequestForgery" Version="1.0.0" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Meziantou.Framework.Http.ServerSideRequestForgery" Version="1.0.0" />
<PackageReference Include="Meziantou.Framework.Http.ServerSideRequestForgery" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Meziantou.Framework.Http.ServerSideRequestForgery --version 1.0.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Meziantou.Framework.Http.ServerSideRequestForgery, 1.0.0"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Meziantou.Framework.Http.ServerSideRequestForgery@1.0.0
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Meziantou.Framework.Http.ServerSideRequestForgery&version=1.0.0
#tool nuget:?package=Meziantou.Framework.Http.ServerSideRequestForgery&version=1.0.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Meziantou.Framework.Http.ServerSideRequestForgery
SSRF protection for SocketsHttpHandler using scheme allow-listing and runtime IP validation.
Usage
using Meziantou.Framework.Http.ServerSideRequestForgery;
var options = new ServerSideRequestForgeryOptions
{
ResolutionStrategy = IpAddressResolutionStrategy.PreferIpv4,
DisallowMixedSafeAndUnsafeIpAddresses = true,
};
options.SafeSchemes.Add("https");
options.SafeSchemes.Add("wss");
options.UnsafeIpNetworks.Add(IPNetwork.Parse("203.0.113.0/24"));
options.SafeIpNetworks.Add(IPNetwork.Parse("198.51.100.10/32"));
var handler = new SocketsHttpHandler();
handler.ConfigureSsrf(options);
using var httpClient = new HttpClient(handler, disposeHandler: true);
Behavior
- Validates request scheme against
SafeSchemes. - Resolves DNS on every connection attempt to avoid TOCTOU vulnerabilities.
- Validates each resolved address against
UnsafeIpNetworksandSafeIpNetworks. - Optionally rejects mixed safe/unsafe DNS responses.
- Uses
IpAddressResolutionStrategyto select the final address (Ipv4Only,Ipv6Only,PreferIpv4,Random,RoundRobin).
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
-
net8.0
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
-
net9.0
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.0.0 | 77 | 5/18/2026 |