feat: block CONNECT tunnels to private/reserved IP ranges (#23109)

## Description

Blocks `CONNECT` tunnels to private and reserved IP ranges in
aibridgeproxyd, preventing the proxy from being used to reach internal
networks.

The Coder access URL is always exempt (hostname+port match) so the proxy
can reach its own deployment. It is possible to exempt additional ranges
via `CODER_AIBRIDGE_PROXY_ALLOWED_PRIVATE_CIDRS`.

DNS rebinding is handled differently per path:
* Direct (no upstream proxy): validate the resolved IP right before the
TCP dial, no window between check and connect.
* Upstream proxy: Resolves and checks before forwarding to the upstream
dialer. A small rebinding window exists since the upstream proxy
re-resolves independently.

## Changes

* Add blocked IP denylist covering private, reserved, and
special-purpose ranges
* Add `AllowedPrivateCIDRs` option with CLI flag and env var
* Wire IP checks into `proxy.ConnectDial` for both upstream and direct
paths
* Add tests for blocked/allowed cases across direct dial, upstream
proxy, CIDR exemptions, and CoderAccessURL exemption

Notes: documentation will be handled in a follow-up PR.
Closes: https://github.com/coder/security/issues/124
This commit is contained in:
Susana Ferreira
2026-03-20 09:49:26 +00:00
committed by GitHub
parent 06c50d13ad
commit 139594a4f4
13 changed files with 563 additions and 59 deletions
+3
View File
@@ -163,6 +163,9 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
"agent_stat_refresh_interval": 0,
"ai": {
"aibridge_proxy": {
"allowed_private_cidrs": [
"string"
],
"cert_file": "string",
"domain_allowlist": [
"string"