Skip to content

basalt / webhooks/src / DEFAULT_BLOCKED_PORTS

Variable: DEFAULT_BLOCKED_PORTS ​

> const DEFAULT_BLOCKED_PORTS: readonly number[]

Defined in: webhooks/src/ssrf.ts:149

Destination ports the default port policy refuses even at or above 1024: ports registered to databases, caches, message brokers, cluster control planes, proxies and remote-administration services. None of them has any business receiving a webhook, and several speak line- or text-based protocols a crafted POST body can drive cross-protocol (Redis, memcached, SMTP-style brokers) — on a public host, too: the private-range guard does not help when the target is someone else's exposed Redis.

Released under the MIT License.