AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Core: SSRF-Safe Transports Drop Streaming Request Bodies And Crash On Internationalized Hostnames

SSRFSafeTransport and SSRFSafeSyncTransport reconstruct pinned requests using request.content and hostname.encode('ascii'). This raises httpx.RequestNotRead for streaming bodies (generators, async generators, files, multipart) and UnicodeEncodeError for internationalized domain names, causing silent failures or crashes in URL-based utilities such as HTMLHeaderTextSplitter and ChatOpenAI token counting.

highConfidence 95%Langchain-CoreAffected V1.6.2

Origin Analysis

The transport validation code rebuilds the httpx.Request for the pinned IP by accessing request.content, which httpx does not buffer for non-ByteStream bodies, and by encoding the Unicode hostname to ASCII instead of using the already IDNA-encoded A-label from request.url.raw_host.
Run the provided Python probe with SSRFSafeSyncTransport, patching getaddrinfo to return a public IP. POST a streaming generator body (content=streaming_body()), POST a multipart file upload, or GET an IDN URL such as https://münchen.example/u. The first two raise httpx.RequestNotRead; the third raises UnicodeEncodeError. Existing tests do not cover these because they use bodyless ASCII GETs.

Fixing Code Block

Edge Case Audit

This changes the sni_hostname extension from bytes to str. Update any tests or code that assert bytes (the existing test pins bytes and must be corrected). The fix is backward-compatible for ASCII hostnames but may expose previously latent mismatches if downstream consumers expected bytes. For rollback, revert to request.content and hostname.encode('ascii'), but streaming bodies, multipart uploads, and IDN hostnames will remain broken. Ensure httpx/httpcore versions are compatible with str server_hostname.

Ecosystem Topology