From 4d585fb2886778f133a1fcebb1e8fa831d762f64 Mon Sep 17 00:00:00 2001 From: Ulas Kalayci Date: Mon, 20 Apr 2026 23:40:38 +0200 Subject: [PATCH] fix(calendar): extend SSRF guard to cover fd00::/8 IPv6 ULA range --- server/services/ics-subscription.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server/services/ics-subscription.js b/server/services/ics-subscription.js index e324a7a..595a51b 100644 --- a/server/services/ics-subscription.js +++ b/server/services/ics-subscription.js @@ -20,7 +20,7 @@ const FETCH_TIMEOUT_MS = 15_000; const PRIVATE_RANGES = [ /^127\./, /^10\./, /^172\.(1[6-9]|2\d|3[01])\./, /^192\.168\./, - /^169\.254\./, /^::1$/, /^fc/i, /^fe[89ab]/i, + /^169\.254\./, /^::1$/, /^f[cd]/i, /^fe[89ab]/i, ]; const syncingNow = new Set();