fix(security): drop URLhaus feed, validate CIDR ranges, pass unknown client IPs
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m46s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m40s

This commit is contained in:
openhands committed 2026-09-24 19:19:22 +02:00
1 parent 7392b843ad
commit 7f6febf906
4 files changed
+78 -12

No files matched your search

+11 -6
View File
@@ -848,12 +848,17 @@ bash cms security blocklists
Defaults: Spamhaus DROP/EDROP, DShield, CINS, Greensnow, StopForumSpam,
Binary Defense, blocklist.de, Emerging Threats, BruteForceBlocker, abuse.ch
Feodo/SSLBL/URLhaus, Botvrij, IPsum, Firehol ipsets and Tor exit nodes
(26 sources). The largest commercial/crowdsourced lists (AbuseIPDB, MaxMind,
Cisco Talos, AlienVault OTX) are not included because they require an account
or API key; IPsum already aggregates ~30 additional feeds. No account is
needed, but internet access is — only for fetching; detection and blocking
remain local. Sync hourly as a cron job:
Feodo/SSLBL, Botvrij, IPsum, Firehol ipsets and Tor exit nodes
(25 sources). URLhaus was removed because its `text_online` feed lists URLs,
not IPs; a malformed token in it could otherwise expand into a bogus
huge CIDR. The validator only accepts whole-line bare IPs or proper CIDRs,
enforces sane prefix bounds and drops reserved/private/loopback space, so a
bad source entry can never block the origin or internal traffic. The largest
commercial/crowdsourced lists (AbuseIPDB, MaxMind, Cisco Talos, AlienVault
OTX) are not included because they require an account or API key; IPsum
already aggregates ~30 additional feeds. No account is needed, but internet
access is — only for fetching; detection and blocking remain local. Sync
hourly as a cron job:
```bash
bash cms security blocklists-install-cron