Skip to content

Reject non-localhost Host headers on the DevTools JSON endpoint - #42

Merged
bmeurer merged 1 commit into
mainfrom
fix-host-check
Oct 8, 2026
Merged

bmeurer merged 1 commit into
mainfrom
fix-host-check

Conversation

@bmeurer

@bmeurer bmeurer commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

On Vite 5.x and 6.x, the synchronous body of plugin configureServer hooks executes before Vite registers hostCheckMiddleware (CVE-2025-24010). Because our endpoint middleware is registered in the synchronous body of configureServer (and cannot be moved to a post-hook without being intercepted by Vite's htmlFallbackMiddleware in SPA mode), validate the Host header directly against localhost (localhost, *.localhost, 127.0.0.0/8, [::1]) and reject non-localhost requests with HTTP 403 to prevent DNS rebinding attacks from reading the workspace root path and UUID.

TAG=agy
CONV=7701f19a-25ab-49bf-9131-831a137a7977

On Vite 5.x and 6.x, the synchronous body of plugin configureServer hooks executes before Vite registers hostCheckMiddleware (CVE-2025-24010). Because our endpoint middleware is registered in the synchronous body of configureServer (and cannot be moved to a post-hook without being intercepted by Vite's htmlFallbackMiddleware in SPA mode), validate the Host header directly against localhost (localhost, *.localhost, 127.0.0.0/8, [::1]) and reject non-localhost requests with HTTP 403 to prevent DNS rebinding attacks from reading the workspace root path and UUID.

TAG=agy
CONV=7701f19a-25ab-49bf-9131-831a137a7977
@bmeurer
bmeurer merged commit 58481eb into main Oct 8, 2026
6 checks passed
@bmeurer
bmeurer deleted the fix-host-check branch October 8, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant