Soenneker.Validators.IpAddresses.Ssrf 4.0.21

Prefix Reserved
dotnet add package Soenneker.Validators.IpAddresses.Ssrf --version 4.0.21
                    
NuGet\Install-Package Soenneker.Validators.IpAddresses.Ssrf -Version 4.0.21
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Soenneker.Validators.IpAddresses.Ssrf" Version="4.0.21" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Soenneker.Validators.IpAddresses.Ssrf" Version="4.0.21" />
                    
Directory.Packages.props
<PackageReference Include="Soenneker.Validators.IpAddresses.Ssrf" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Soenneker.Validators.IpAddresses.Ssrf --version 4.0.21
                    
#r "nuget: Soenneker.Validators.IpAddresses.Ssrf, 4.0.21"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Soenneker.Validators.IpAddresses.Ssrf@4.0.21
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Soenneker.Validators.IpAddresses.Ssrf&version=4.0.21
                    
Install as a Cake Addin
#tool nuget:?package=Soenneker.Validators.IpAddresses.Ssrf&version=4.0.21
                    
Install as a Cake Tool

alternate text is missing from this package README image alternate text is missing from this package README image alternate text is missing from this package README image alternate text is missing from this package README image

Soenneker.Validators.IpAddresses.Ssrf

Conservatively accepts public IPv4 and IPv6 literals while rejecting private, local, reserved, documentation, transition, and other special-purpose ranges commonly involved in SSRF.

Install

dotnet add package Soenneker.Validators.IpAddresses.Ssrf

Registration

using Soenneker.Validators.IpAddresses.Ssrf.Registrars;
using Microsoft.Extensions.DependencyInjection;

services.AddSsrfIpAddressValidatorAsSingleton();

The validator is stateless. Singleton registration is appropriate for most applications; AddSsrfIpAddressValidatorAsScoped() is also available.

Validate a literal

using Soenneker.Validators.IpAddresses.Ssrf.Abstract;

bool publicIpv4 = validator.Validate("8.8.8.8");
bool privateIpv4 = validator.Validate("10.0.0.1");
bool loopbackIpv6 = validator.Validate("::1");

// true, false, false

The string overload accepts canonical dotted-decimal IPv4 and standard IPv6 literal forms. It rejects hostnames, IPv4 parts with leading zeroes, IPv6 zone/scope identifiers, malformed compression, and null or empty input. It parses without DNS resolution.

An IPAddress overload is available when parsing has already occurred:

bool allowed = validator.Validate(resolvedAddress);

Scoped IPv6 IPAddress instances are rejected when ScopeId is nonzero. IPv4-mapped and IPv4-compatible IPv6 addresses are classified using their embedded IPv4 destination, preventing loopback or private IPv4 from being hidden inside IPv6 notation.

Classification policy

IPv4 rejection includes unspecified, private-use, carrier-grade NAT, loopback, link-local, protocol-assignment, documentation, 6to4-relay, benchmarking, multicast, and reserved ranges.

IPv6 acceptance is restricted to the allocated 2000::/3 global-unicast range, with additional rejection for IETF protocol assignments, documentation blocks, deprecated 6to4, and unique-local addresses. This is deliberately conservative: a globally reachable special-purpose exception may still be rejected.

The policy is implemented as compiled prefix checks based on the IANA IPv4 and IPv6 special-purpose registries. It is not downloaded or updated at runtime.

Using it in SSRF defenses

This validator is one component, not a complete SSRF defense. For a user-supplied hostname or URL:

  1. Restrict schemes and ports.
  2. Resolve the hostname and reject the request if any candidate address is disallowed.
  3. Ensure the HTTP connection is made to the validated address, not a later unvalidated DNS result.
  4. Revalidate every redirect target or disable redirects.
  5. Apply destination allowlists where possible.

Validating once and then performing a normal hostname request remains vulnerable to DNS rebinding and time-of-check/time-of-use changes. The result also says nothing about application-layer safety on an otherwise public host.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Soenneker.Validators.IpAddresses.Ssrf:

Package Downloads
Soenneker.Utils.HttpClientCache.Ssrf

SSRF-safe, DNS-rebinding-resistant HttpClient caching.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
4.0.21 140 9/24/2026
4.0.19 412 9/15/2026
4.0.18 92 9/15/2026
4.0.17 355 9/14/2026
4.0.16 132 9/14/2026
4.0.15 417 9/8/2026
4.0.14 235 9/4/2026
4.0.13 129 9/4/2026
4.0.12 179 8/31/2026
4.0.11 138 8/30/2026
4.0.10 163 8/30/2026
4.0.9 132 8/29/2026
4.0.8 116 8/29/2026
4.0.7 421 8/12/2026
4.0.6 297 8/1/2026
4.0.5 117 8/1/2026
4.0.4 152 8/1/2026
4.0.3 137 7/30/2026
4.0.2 143 7/28/2026
4.0.1 217 7/27/2026