Fix SSRF / credential exfiltration via api_endpoint (b/565094291) - #644
Draft
erinlimbogoogle wants to merge 1 commit into
Draft
erinlimbogoogle wants to merge 1 commit into
erinlimbogoogle wants to merge 1 commit into
Conversation
…owlist QueryDataAPIGenerator read api_endpoint from the client-supplied model config without validation and then (a) passed it to DataChatServiceClient, which attaches ADC credentials, and (b) on the REST path interpolated it into the request URL and sent the server's ADC bearer token in the Authorization header. A caller able to submit an EvalConfig could set api_endpoint to a host they control and receive the server's credentials. Validate api_endpoint in __init__, before the client is constructed, so both the gRPC and REST paths only ever target an allowlisted host: geminidataanalytics.googleapis.com <prefix>-geminidataanalytics.googleapis.com (autopush/staging) <label>.geminidataanalytics.googleapis.com (regional) <label>.sandbox.googleapis.com (test environments) Only bare hostnames are accepted. Schemes, paths, ports, userinfo and suffix lookalikes raise ValueError. Values are trimmed and lowercased. Fixes b/565094291
erinlimbogoogle
force-pushed
the
fix/querydata-endpoint-ssrf
branch
from
October 3, 2026 16:07
adaef30 to
624070b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix SSRF / credential exfiltration via
api_endpoint(b/565094291)📌 Summary
b/565094291QueryDataAPIGenerator__init__prior to client creationQueryDataAPIGeneratorpreviously accepted an arbitraryapi_endpointfrom client-supplied model configurations (EvalConfig). The server then transmitted its Application Default Credentials (ADC) to that endpoint:DataChatServiceClient(client_options=...)Authorization: Bearer <token>request headerImpact: A caller submitting an
EvalConfigcould steer the server's access token to an attacker-controlled host.💡 Solution & Validation Rules
The
api_endpointparameter is now validated in__init__before initializing the service client. Hostnames must strictly match an allowlist of bare Google domain patterns:geminidataanalytics.googleapis.comand*-/*prefixes*.sandbox.googleapis.comhttps://), paths, ports (:443), userinfo, or suffix lookalikesValueError✅ Test Coverage
Added 4 comprehensive unit tests:
ValueError