Kong/insomnia · error · Error
Failed to resolve host. "${hostname}" resolves to a private
Error message
Failed to resolve host. "${hostname}" resolves to a private or loopback address. What it means
Error "Failed to resolve host. "${hostname}" resolves to a private or loopback address." thrown in Kong/insomnia.
Source
Thrown at packages/insomnia-inso/src/commands/lint-specification.ts:41
let url: URL;
try {
url = new URL(href);
} catch {
return false;
}
if (url.protocol !== 'https:') {
return false;
}
return Boolean(url.hostname) && !isPrivateOrLoopbackHost(url.hostname.toLowerCase());
}
// Block hosts that resolve to private/loopback addresses (e.g. *.localtest.me → 127.0.0.1),
// Note: This is duplicated in insomnia's main/lint-process.mjs. Remember to mirror changes there as well.
async function assertResolvesToPublicHost(hostname: string): Promise<void> {
const records = await dns.lookup(hostname, { all: true });
for (const { address } of records) {
if (isPrivateOrLoopbackHost(address)) {
throw new Error(`Failed to resolve host. "${hostname}" resolves to a private or loopback address.`);
}
}
}
// Note: This is duplicated in insomnia's main/lint-process.mjs. Remember to mirror changes there as well.
const safeHttpResolver = {
async resolve(ref: { href: () => string }): Promise<string> {
const href = ref.href();
if (!isSafeRefUrl(href)) {
throw new Error(`Failed to resolve "${href}". Only https URLs to public hosts are allowed.`);
}
await assertResolvesToPublicHost(new URL(href).hostname.toLowerCase());
const response = await fetch(href, { redirect: 'error', signal: AbortSignal.timeout(10_000) });
if (!response.ok) {
throw new Error(`Failed to fetch "${href}": ${response.status} ${response.statusText}`);
}
return response.text();
},View on GitHub (pinned to d9bb2b0142)
When it happens
Trigger: Thrown at packages/insomnia-inso/src/commands/lint-specification.ts:41 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of Kong/insomnia@d9bb2b0142 (2026-08-26).
Data as JSON: /api/errors/99938341a0492762.
Report an issue: GitHub.