{"record":{"id":"55e7dd3b8e9b329a","repo":"google-gemini/gemini-cli","slug":"failed-to-verify-if-url-resolves-to-private-ip","errorCode":null,"errorMessage":"Failed to verify if URL resolves to private IP","messagePattern":"Failed to verify if URL resolves to private IP","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/core/src/utils/fetch.ts","lineNumber":363,"sourceCode":"    hostname.endsWith('.localhost') ||\n    hostname.endsWith('.local') ||\n    hostname.endsWith('.internal')\n  ) {\n    return true;\n  }\n\n  if (net.isIP(hostname)) {\n    return isAddressPrivate(hostname);\n  }\n\n  try {\n    const addresses = await lookup(hostname, { all: true });\n    if (!addresses || addresses.length === 0) {\n      return true;\n    }\n    return addresses.some((addr) => isAddressPrivate(addr.address));\n  } catch (error) {\n    throw new Error('Failed to verify if URL resolves to private IP', {\n      cause: error,\n    });\n  }\n}\n\n/**\n * Checks if a URL targets or resolves to a private, loopback, or reserved network.\n * Fails closed on resolution errors or timeouts.\n *\n * Checks performed:\n * - RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)\n * - Loopback addresses (127.0.0.0/8, ::1)\n * - Cloud Metadata and link-local addresses (169.254.0.0/16, fe80::/10)\n * - Carrier-Grade NAT (100.64.0.0/10)\n * - IANA benchmark testing range (198.18.0.0/15)\n * - IPv6 unique local addresses (fc00::/7) and IPv4-mapped IPv6 (::ffff:x.x.x.x)\n * - Internal top-level domains (.localhost, .local, .internal)\n * - Multi-IP resolution: rejects if ANY resolved address is private or reserved","sourceCodeStart":345,"sourceCodeEnd":381,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/utils/fetch.ts#L345-L381","documentation":"DNS resolution of the hostname succeeded at the API level but lookup threw (or the code path errored), so the private-IP safety check could not complete. This is a fail-closed guard: because the tool cannot prove the host resolves to a public address, it rejects resolution errors instead of allowing the request.","triggerScenarios":"Thrown at packages/core/src/utils/fetch.ts:363 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Check DNS availability/resolver config and retry","Verify the hostname is spelled correctly and resolvable from this machine","Inspect error.cause for the underlying DNS error code (e.g. ENOTFOUND, EAI_AGAIN)"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}