Soenneker.Utils.HttpClientCache.Ssrf
4.0.71
Prefix Reserved
dotnet add package Soenneker.Utils.HttpClientCache.Ssrf --version 4.0.71
NuGet\Install-Package Soenneker.Utils.HttpClientCache.Ssrf -Version 4.0.71
<PackageReference Include="Soenneker.Utils.HttpClientCache.Ssrf" Version="4.0.71" />
<PackageVersion Include="Soenneker.Utils.HttpClientCache.Ssrf" Version="4.0.71" />
<PackageReference Include="Soenneker.Utils.HttpClientCache.Ssrf" />
paket add Soenneker.Utils.HttpClientCache.Ssrf --version 4.0.71
#r "nuget: Soenneker.Utils.HttpClientCache.Ssrf, 4.0.71"
#:package Soenneker.Utils.HttpClientCache.Ssrf@4.0.71
#addin nuget:?package=Soenneker.Utils.HttpClientCache.Ssrf&version=4.0.71
#tool nuget:?package=Soenneker.Utils.HttpClientCache.Ssrf&version=4.0.71
Soenneker.Utils.HttpClientCache.Ssrf
SSRF-safe, DNS-rebinding-resistant HttpClient caching.
Installation
dotnet add package Soenneker.Utils.HttpClientCache.Ssrf
Registration
using Soenneker.Utils.HttpClientCache.Ssrf.Registrars;
services.AddSsrfHttpClientCacheAsSingleton();
AddSsrfHttpClientCacheAsScoped() is also available. Both methods register the underlying
Soenneker.Utils.HttpClientCache service with the matching lifetime when it has not already
been registered.
Usage
using Soenneker.Utils.HttpClientCache.Ssrf.Abstract;
public sealed class RemoteDocumentClient
{
private readonly ISsrfHttpClientCache _clientCache;
public RemoteDocumentClient(ISsrfHttpClientCache clientCache)
{
_clientCache = clientCache;
}
public async ValueTask<string> Download(Uri uri, CancellationToken cancellationToken)
{
HttpClient client = await _clientCache.Get("remote-documents", cancellationToken);
return await client.GetStringAsync(uri, cancellationToken);
}
}
The cache implements the same API as IHttpClientCache, including synchronous and asynchronous
option factories, cache removal, and disposal. An id identifies one cached client within this
cache instance. Configure a given ID consistently: as with the underlying cache, the options
factory is used only when that client is first created.
Security behavior
- DNS is resolved when a connection is opened.
- Every resolved address must be publicly routable.
- The socket connects directly to the validated address set, preventing a second DNS lookup from changing the destination.
- Redirect destinations pass through the same connection validation.
- Loopback, private, link-local, carrier-grade NAT, documentation, benchmark, multicast, and reserved address ranges are blocked for IPv4 and IPv6.
- Proxies, custom
HttpClientHandlerinstances, and customSslOptionsare rejected because they expand or bypass the cache's controlled transport configuration.
Validation happens when a connection is opened, not when Get returns a client. A hostname that
resolves to any blocked address is rejected rather than falling back to another address. This
protects outbound connections; it does not impose an application-level allowlist for hosts or
paths.
The caller owns neither the returned HttpClient nor its handler. Use Remove/RemoveSync when a
cached client is no longer needed, or dispose the cache with its dependency-injection scope.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Soenneker.Utils.HttpClientCache (>= 4.0.2098)
- Soenneker.Validators.IpAddresses.Ssrf (>= 4.0.21)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Soenneker.Utils.HttpClientCache.Ssrf:
| Package | Downloads |
|---|---|
|
Soenneker.N8n.HttpClients
Provides cached, authenticated HTTP clients for one or more n8n servers. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.71 | 0 | 9/29/2026 |
| 4.0.70 | 0 | 9/29/2026 |
| 4.0.69 | 66 | 9/25/2026 |
| 4.0.68 | 37 | 9/25/2026 |
| 4.0.67 | 44 | 9/25/2026 |
| 4.0.65 | 71 | 9/25/2026 |
| 4.0.64 | 47 | 9/24/2026 |
| 4.0.63 | 252 | 9/17/2026 |
| 4.0.62 | 123 | 9/16/2026 |
| 4.0.61 | 119 | 9/16/2026 |
| 4.0.60 | 108 | 9/16/2026 |
| 4.0.59 | 105 | 9/16/2026 |
| 4.0.58 | 175 | 9/15/2026 |
| 4.0.57 | 140 | 9/15/2026 |
| 4.0.56 | 183 | 9/14/2026 |
| 4.0.55 | 123 | 9/14/2026 |
| 4.0.54 | 127 | 9/13/2026 |
| 4.0.53 | 98 | 9/13/2026 |
| 4.0.52 | 176 | 9/13/2026 |
| 4.0.51 | 95 | 9/12/2026 |