google-gemini/gemini-cli · error · Error
Failed to verify if URL resolves to private IP
Error message
Failed to verify if URL resolves to private IP
What it means
DNS resolution of the hostname succeeded at the API level but lookup threw (or the code path errored), so the private-IP safety check could not complete. This is a fail-closed guard: because the tool cannot prove the host resolves to a public address, it rejects resolution errors instead of allowing the request.
Solutions
- Check DNS availability/resolver config and retry
- Verify the hostname is spelled correctly and resolvable from this machine
- Inspect error.cause for the underlying DNS error code (e.g. ENOTFOUND, EAI_AGAIN)
Defensive patterns
Strategy: try-catch
When it happens
Trigger: Thrown at packages/core/src/utils/fetch.ts:363 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/55e7dd3b8e9b329a.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/utils/fetch.ts:363
hostname.endsWith('.localhost') ||
hostname.endsWith('.local') ||
hostname.endsWith('.internal')
) {
return true;
}
if (net.isIP(hostname)) {
return isAddressPrivate(hostname);
}
try {
const addresses = await lookup(hostname, { all: true });
if (!addresses || addresses.length === 0) {
return true;
}
return addresses.some((addr) => isAddressPrivate(addr.address));
} catch (error) {
throw new Error('Failed to verify if URL resolves to private IP', {
cause: error,
});
}
}
/**
* Checks if a URL targets or resolves to a private, loopback, or reserved network.
* Fails closed on resolution errors or timeouts.
*
* Checks performed:
* - RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
* - Loopback addresses (127.0.0.0/8, ::1)
* - Cloud Metadata and link-local addresses (169.254.0.0/16, fe80::/10)
* - Carrier-Grade NAT (100.64.0.0/10)
* - IANA benchmark testing range (198.18.0.0/15)
* - IPv6 unique local addresses (fc00::/7) and IPv4-mapped IPv6 (::ffff:x.x.x.x)
* - Internal top-level domains (.localhost, .local, .internal)
* - Multi-IP resolution: rejects if ANY resolved address is private or reservedView on GitHub (pinned to 6a466a7e2f)