api-security
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalycsharp-dotnet.md
LOWAnomalyLOW
csharp-dotnet.md
No evidence of intentional malware or supply-chain sabotage is present. The fetch-preview endpoint is a legitimate but security-sensitive SSRF feature. Its safety depends on the omitted UrlValidator implementation and HTTP client redirect/DNS behavior. The fragment should be reviewed to ensure resolved IP validation, redirect revalidation or disabling, complete reserved-range coverage, response-size limits, and restricted outbound ports/domains.
Confidence: 94%Severity: 58%
Audit Metadata