Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.257 ·

SSRF/metadata-endpoint protection for outbound requests

Outbound requests to cloud metadata hostnames and private, link-local or loopback ranges are now blocked.

TierYou'll noticehow much it should matter to you
Useful2my rating, 1 to 5
Signal2worth watching, 1 to 5
AreaNetworkwhat it touches
KindImprovementsin v2.1.257,
You'll notice

Outbound requests to cloud metadata hostnames and private, link-local or loopback ranges are now blocked.

New IP and hostname classification logic recognizes cloud metadata hostnames, including metadata.google.internal and instance-data endpoints, along with private, link-local, loopback, NAT64, and 6to4 IPv4-mapped IPv6 ranges, as unsafe destinations. This is used to block outbound requests to cloud metadata services and internal addresses.

See this entry in the whole of v2.1.257 →

Feedback