Skip to main content

safehttpx

A small Python library created to help developers protect their applications from Server Side Request Forgery (SSRF) attacks. It implements an asynchronous GET method called safehttpx.get(), which is a wrapper around httpx2.AsyncClient.get() (HTTPX2, the maintained fork of httpx) while performing DNS validation on the supplied URL using Google DNS.

It also implements mitigation for DNS rebinding attacks.

Why?

Server Side Request Forgery (SSRF) attacks can be particularly dangerous as they allow attackers to make arbitrary HTTP requests from your server, potentially accessing sensitive internal services that are normally unreachable from the internet. This could enable attackers to scan internal networks, access metadata services in cloud environments (like "AWS Instance Metadata Service"), or hit internal APIs - all while appearing to come from your trusted server. By validating URLs against public DNS servers and implementing protections against DNS rebinding, safehttpx helps prevent attackers from coercing your application into making requests to internal or otherwise restricted network resources.

Usage

Installation

$ pip install safehttpx

Also avalaible through Conda

$ conda install safehttpx -c conda-forge

or

$ mamba install safehttpx -c conda-forge

Basic Usage

import safehttpx as sh

await sh.get("https://huggingface.co")
>>> <Response [200 OK]>

await sh.get("http://127.0.0.1")
>>> ValueError: Hostname 127.0.0.1 failed validation

Note on Async Usage:

The example snippets above will work in environments like IPython or Jupyter notebooks where an asyncio event loop is already running. For regular Python scripts, you'll need to explicitly create and run an asyncio event loop. Here's how you can structure your code to use safehttpx in a standard Python script:

import asyncio
import safehttpx as sh

asyncio.run(sh.get("https://huggingface.co"))
>>> <Response [200 OK]>

Whitelisted Domains

You may want to whitelist certain domains from being validated. For example, if you are running code on a server that implements DNS splitting, then even public URLs may appear as internal URLs. You can whitelist domains like this:

import safehttpx as sh

PUBLIC_HOSTNAME_WHITELIST = ["hf.co", "huggingface.co"]

await sh.get("https://huggingface.co", domain_whitelist=PUBLIC_HOSTNAME_WHITELIST)
>>> <Response [200 OK]>

Custom Transports (Advanced)

If you know what you are doing, and what to pass in a custom instance of httpx2.AsyncBaseTransport, you can use the _transport parameter in sh.get(). Setting this to False explicitly will use no secure transport (effectively making sh.get equivalent to httpx2.AsyncClient.get()).

More Information

This library was created as a result of Trail of Bits' security audit of Gradio 5 (Hugging Face), and is used in the Gradio library to make secure requests to arbitrary user-specified URLs. We are releasing this as a standalone library so that other developers can benefit from our learnings. In the interest of transparency and the spirit of open-source, we are making the full security audit public.

If you find a security issue in this library, please email the Gradio team at gradio-team@huggingface.co. Thanks!

Metadata

Release files for safehttpx 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for safehttpx 0.2.0
File Size Uploaded
safehttpx-0.2.0.tar.gz 10.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for safehttpx 0.2.0
File Interpreter ABI Platform
safehttpx-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 19.8 kB

Release files / safehttpx-0.2.0.tar.gz

Download URL safehttpx-0.2.0.tar.gz
Size 10.6 kB
Tags Source
SHA-256 checksum
How to use checksums
bd698a5a1730777040ccfdac0aef7a7bdb10f59931796c4c99c003dc90dff281
BLAKE2b-256 checksum
How to use checksums
259085fcebcef2005822fa1724c6669518c552b2a2ae293089610aa5b657da22
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / safehttpx-0.2.0-py3-none-any.whl

Download URL safehttpx-0.2.0-py3-none-any.whl
Size 9.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ffb8a246ea541abd79febba40591e3fc380380636f75376c0dff0aed6e3d7e29
BLAKE2b-256 checksum
How to use checksums
3ec34ad7c04204494996a6945223ab07e551f19a5d2f35ed59e658e7febe6494
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page