github MakazhanAlpamys/Soup v0.75.2
v0.75.2 — outbound endpoint checks refuse private addresses

3 hours ago

A security patch release for the 0.75 line. It carries one hardening change and nothing else; everything merged on main since 0.75.0 ships in the next minor release.

What's New

  • Outbound endpoint checks refuse private IP literals on every scheme. soup data generate --api-base, the vLLM provider and the commands that use it, judge URLs in soup eval judge, eval-gate suites, soup ship --judge-model / eval.ship.judge_model, training.online_dpo_judge, and the Web UI chat proxy now refuse a private, link-local or reserved IP literal over https as well as http. Loopback still works; address a server on your network by its hostname. training.online_dpo_judge is checked when soup.yaml loads, not only when the trainer starts.
  • http://0.0.0.0 is no longer treated as local by soup data generate --api-base and the Web UI chat proxy; use localhost or 127.0.0.1.
  • 100.64.0.0/10 and fec0::/10 are non-public for every check that already refused private addresses (webhooks, the OTLP endpoint, telemetry, hub endpoints over HTTP, and soup ingest --pull, where --allow-private-host admits them).
  • Non-ASCII spellings of an address are classified as that address. An IP literal written with non-ASCII digits or label separators is read the way the HTTP client folds it to ASCII before it connects. This applies to every check above.

Fixed

  • soup ship checks --judge-model before it builds the base and tuned models. It used to load both and only then stop with a usage error.
  • The Web UI chat proxy answers 400, not 500, for an endpoint URL that does not parse.

Install / Upgrade

pip install -U "soup-cli==0.75.2"
# or
pipx upgrade soup-cli

Security

  • Outbound endpoint validation (GHSA-9f49-hqpf-c849). Upgrade to 0.75.2. Until then, do not run an untrusted soup.yaml, eval-gate suite or .can package that sets judge_model, online_dpo_judge or eval.ship.judge_model, and keep soup ui bound to loopback with its token private.

Known Limitations

  • Hostnames are not resolved: a hostname that resolves to a private address is still accepted, as by every other endpoint check in Soup.
  • HF_ENDPOINT and the hub endpoint variables refuse private IP literals over plain HTTP only; they come from the operator's environment.
  • There is no opt-in for a private TLS endpoint addressed by an IP literal; use a hostname.
  • The checks are found by their shape, so a new outbound call could skip them; a ratchet over every outbound call site is #1547.
  • Loopback spellings differ between settings: http://[::1] passes the judge and vLLM checks but not eval-gate suites, soup ship or the online-DPO trainer (#1548).
  • The refusal names no remedy, and http://0.0.0.0 gets only the generic HTTPS message (#1549).
  • IP-literal parsing depends on the platform's inet_aton and, for 6to4 / NAT64 / Teredo addresses, on the interpreter's ipaddress tables (#1550).

Contributors

  • @abdugafforov-bobur reported that the outbound endpoint checks accepted an https:// URL naming a private IP literal, with a clear reproduction.

The same fix is on main as #1527.

Don't miss a new Soup release

NewReleases is sending notifications on new releases.