google-gemini/gemini-cli · error · Error

Failed to verify if URL resolves to private IP

Error message

Failed to verify if URL resolves to private IP

What it means

DNS resolution of the hostname succeeded at the API level but lookup threw (or the code path errored), so the private-IP safety check could not complete. This is a fail-closed guard: because the tool cannot prove the host resolves to a public address, it rejects resolution errors instead of allowing the request.

Solutions

  1. Check DNS availability/resolver config and retry
  2. Verify the hostname is spelled correctly and resolvable from this machine
  3. Inspect error.cause for the underlying DNS error code (e.g. ENOTFOUND, EAI_AGAIN)
Defensive patterns

Strategy: try-catch

When it happens

Trigger: Thrown at packages/core/src/utils/fetch.ts:363 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/55e7dd3b8e9b329a. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/fetch.ts:363

    hostname.endsWith('.localhost') ||
    hostname.endsWith('.local') ||
    hostname.endsWith('.internal')
  ) {
    return true;
  }

  if (net.isIP(hostname)) {
    return isAddressPrivate(hostname);
  }

  try {
    const addresses = await lookup(hostname, { all: true });
    if (!addresses || addresses.length === 0) {
      return true;
    }
    return addresses.some((addr) => isAddressPrivate(addr.address));
  } catch (error) {
    throw new Error('Failed to verify if URL resolves to private IP', {
      cause: error,
    });
  }
}

/**
 * Checks if a URL targets or resolves to a private, loopback, or reserved network.
 * Fails closed on resolution errors or timeouts.
 *
 * Checks performed:
 * - RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
 * - Loopback addresses (127.0.0.0/8, ::1)
 * - Cloud Metadata and link-local addresses (169.254.0.0/16, fe80::/10)
 * - Carrier-Grade NAT (100.64.0.0/10)
 * - IANA benchmark testing range (198.18.0.0/15)
 * - IPv6 unique local addresses (fc00::/7) and IPv4-mapped IPv6 (::ffff:x.x.x.x)
 * - Internal top-level domains (.localhost, .local, .internal)
 * - Multi-IP resolution: rejects if ANY resolved address is private or reserved

View on GitHub (pinned to 6a466a7e2f)