google-gemini/gemini-cli · error

WEB_FETCH_PROCESSING_ERROR

WEB_FETCH_PROCESSING_ERROR

Error message

Access to blocked or private host ${url} is not allowed.

What it means

The experimental web-fetch path refused the request after its isBlockedHost check determined the (possibly GitHub-normalized) URL targets a private or blocklisted host. This is the tool-level SSRF guard mirroring fetchWithTimeout; the blocked URL is embedded in the message and a warning is logged.

Solutions

  1. Fetch a URL on a public, non-blocklisted host
  2. Verify the final URL after GitHub blob-to-raw conversion points where expected
  3. Add the host to the allowlist if it is a trusted public endpoint being misclassified
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/core/src/tools/web-fetch.ts:629 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/79106f99f5fb49d4. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/tools/web-fetch.ts:629

      return {
        llmContent: `Error: Invalid URL "${this.params.url}"`,
        returnDisplay: `Error: Invalid URL "${this.params.url}"`,
        error: {
          message: `Invalid URL "${this.params.url}"`,
          type: ToolErrorType.INVALID_TOOL_PARAMS,
        },
      };
    }

    // Convert GitHub blob URL to raw URL
    url = convertGithubUrlToRaw(url);

    if (await this.isBlockedHost(url)) {
      const errorMessage = `Access to blocked or private host ${url} is not allowed.`;
      debugLogger.warn(
        `[WebFetchTool] Blocked experimental fetch to host: ${url}`,
      );
      return {
        llmContent: `Error: ${errorMessage}`,
        returnDisplay: `Error: ${errorMessage}`,
        error: {
          message: errorMessage,
          type: ToolErrorType.WEB_FETCH_PROCESSING_ERROR,
        },
      };
    }

    try {
      const response = await retryWithBackoff(
        async () => {
          const res = await fetchWithTimeout(url, URL_FETCH_TIMEOUT_MS, {
            signal,
            headers: {
              Accept:
                'text/markdown, text/plain;q=0.9, application/json;q=0.9, text/html;q=0.8, application/pdf;q=0.7, video/*;q=0.7, */*;q=0.5',
              'User-Agent': USER_AGENT,

View on GitHub (pinned to 6a466a7e2f)