{"record":{"id":"79106f99f5fb49d4","repo":"google-gemini/gemini-cli","slug":"web-fetch-processing-error","errorCode":"WEB_FETCH_PROCESSING_ERROR","errorMessage":"Access to blocked or private host ${url} is not allowed.","messagePattern":"Access to blocked or private host (.+?) is not allowed\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/core/src/tools/web-fetch.ts","lineNumber":629,"sourceCode":"      return {\n        llmContent: `Error: Invalid URL \"${this.params.url}\"`,\n        returnDisplay: `Error: Invalid URL \"${this.params.url}\"`,\n        error: {\n          message: `Invalid URL \"${this.params.url}\"`,\n          type: ToolErrorType.INVALID_TOOL_PARAMS,\n        },\n      };\n    }\n\n    // Convert GitHub blob URL to raw URL\n    url = convertGithubUrlToRaw(url);\n\n    if (await this.isBlockedHost(url)) {\n      const errorMessage = `Access to blocked or private host ${url} is not allowed.`;\n      debugLogger.warn(\n        `[WebFetchTool] Blocked experimental fetch to host: ${url}`,\n      );\n      return {\n        llmContent: `Error: ${errorMessage}`,\n        returnDisplay: `Error: ${errorMessage}`,\n        error: {\n          message: errorMessage,\n          type: ToolErrorType.WEB_FETCH_PROCESSING_ERROR,\n        },\n      };\n    }\n\n    try {\n      const response = await retryWithBackoff(\n        async () => {\n          const res = await fetchWithTimeout(url, URL_FETCH_TIMEOUT_MS, {\n            signal,\n            headers: {\n              Accept:\n                'text/markdown, text/plain;q=0.9, application/json;q=0.9, text/html;q=0.8, application/pdf;q=0.7, video/*;q=0.7, */*;q=0.5',\n              'User-Agent': USER_AGENT,","sourceCodeStart":611,"sourceCodeEnd":647,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/tools/web-fetch.ts#L611-L647","documentation":"The experimental web-fetch path refused the request after its isBlockedHost check determined the (possibly GitHub-normalized) URL targets a private or blocklisted host. This is the tool-level SSRF guard mirroring fetchWithTimeout; the blocked URL is embedded in the message and a warning is logged.","triggerScenarios":"Thrown at packages/core/src/tools/web-fetch.ts:629 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Fetch a URL on a public, non-blocklisted host","Verify the final URL after GitHub blob-to-raw conversion points where expected","Add the host to the allowlist if it is a trusted public endpoint being misclassified"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}