Soenneker.Validators.IpAddresses.Ssrf
4.0.21
Prefix Reserved
dotnet add package Soenneker.Validators.IpAddresses.Ssrf --version 4.0.21
NuGet\Install-Package Soenneker.Validators.IpAddresses.Ssrf -Version 4.0.21
<PackageReference Include="Soenneker.Validators.IpAddresses.Ssrf" Version="4.0.21" />
<PackageVersion Include="Soenneker.Validators.IpAddresses.Ssrf" Version="4.0.21" />
<PackageReference Include="Soenneker.Validators.IpAddresses.Ssrf" />
paket add Soenneker.Validators.IpAddresses.Ssrf --version 4.0.21
#r "nuget: Soenneker.Validators.IpAddresses.Ssrf, 4.0.21"
#:package Soenneker.Validators.IpAddresses.Ssrf@4.0.21
#addin nuget:?package=Soenneker.Validators.IpAddresses.Ssrf&version=4.0.21
#tool nuget:?package=Soenneker.Validators.IpAddresses.Ssrf&version=4.0.21
Soenneker.Validators.IpAddresses.Ssrf
Conservatively accepts public IPv4 and IPv6 literals while rejecting private, local, reserved, documentation, transition, and other special-purpose ranges commonly involved in SSRF.
Install
dotnet add package Soenneker.Validators.IpAddresses.Ssrf
Registration
using Soenneker.Validators.IpAddresses.Ssrf.Registrars;
using Microsoft.Extensions.DependencyInjection;
services.AddSsrfIpAddressValidatorAsSingleton();
The validator is stateless. Singleton registration is appropriate for most applications; AddSsrfIpAddressValidatorAsScoped() is also available.
Validate a literal
using Soenneker.Validators.IpAddresses.Ssrf.Abstract;
bool publicIpv4 = validator.Validate("8.8.8.8");
bool privateIpv4 = validator.Validate("10.0.0.1");
bool loopbackIpv6 = validator.Validate("::1");
// true, false, false
The string overload accepts canonical dotted-decimal IPv4 and standard IPv6 literal forms. It rejects hostnames, IPv4 parts with leading zeroes, IPv6 zone/scope identifiers, malformed compression, and null or empty input. It parses without DNS resolution.
An IPAddress overload is available when parsing has already occurred:
bool allowed = validator.Validate(resolvedAddress);
Scoped IPv6 IPAddress instances are rejected when ScopeId is nonzero. IPv4-mapped and IPv4-compatible IPv6 addresses are classified using their embedded IPv4 destination, preventing loopback or private IPv4 from being hidden inside IPv6 notation.
Classification policy
IPv4 rejection includes unspecified, private-use, carrier-grade NAT, loopback, link-local, protocol-assignment, documentation, 6to4-relay, benchmarking, multicast, and reserved ranges.
IPv6 acceptance is restricted to the allocated 2000::/3 global-unicast range, with additional rejection for IETF protocol assignments, documentation blocks, deprecated 6to4, and unique-local addresses. This is deliberately conservative: a globally reachable special-purpose exception may still be rejected.
The policy is implemented as compiled prefix checks based on the IANA IPv4 and IPv6 special-purpose registries. It is not downloaded or updated at runtime.
Using it in SSRF defenses
This validator is one component, not a complete SSRF defense. For a user-supplied hostname or URL:
- Restrict schemes and ports.
- Resolve the hostname and reject the request if any candidate address is disallowed.
- Ensure the HTTP connection is made to the validated address, not a later unvalidated DNS result.
- Revalidate every redirect target or disable redirects.
- Apply destination allowlists where possible.
Validating once and then performing a normal hostname request remains vulnerable to DNS rebinding and time-of-check/time-of-use changes. The result also says nothing about application-layer safety on an otherwise public host.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Soenneker.Validators.Validator (>= 4.0.742)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Soenneker.Validators.IpAddresses.Ssrf:
| Package | Downloads |
|---|---|
|
Soenneker.Utils.HttpClientCache.Ssrf
SSRF-safe, DNS-rebinding-resistant HttpClient caching. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.21 | 140 | 9/24/2026 |
| 4.0.19 | 412 | 9/15/2026 |
| 4.0.18 | 92 | 9/15/2026 |
| 4.0.17 | 355 | 9/14/2026 |
| 4.0.16 | 132 | 9/14/2026 |
| 4.0.15 | 417 | 9/8/2026 |
| 4.0.14 | 235 | 9/4/2026 |
| 4.0.13 | 129 | 9/4/2026 |
| 4.0.12 | 179 | 8/31/2026 |
| 4.0.11 | 138 | 8/30/2026 |
| 4.0.10 | 163 | 8/30/2026 |
| 4.0.9 | 132 | 8/29/2026 |
| 4.0.8 | 116 | 8/29/2026 |
| 4.0.7 | 421 | 8/12/2026 |
| 4.0.6 | 297 | 8/1/2026 |
| 4.0.5 | 117 | 8/1/2026 |
| 4.0.4 | 152 | 8/1/2026 |
| 4.0.3 | 137 | 7/30/2026 |
| 4.0.2 | 143 | 7/28/2026 |
| 4.0.1 | 217 | 7/27/2026 |