Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Sandbox network proxy checks what allowed hostnames resolve to, with a new deniedResolvedAddresses setting

The sandbox now refuses allowed hostnames that resolve to loopback, cloud-metadata and similar addresses, and deniedResolvedAddresses adds your own ranges

Group of 2 Use it now Notable No documentation found New Features
JSON All of v2.1.284
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
SandboxArea: what it touches
New FeaturesKind: in v2.1.284,
What probably matters to youSection of the release

What

The sandbox can limit which websites commands run by Claude may reach. Its network proxy, the go-between that forwards those connections, now also checks the IP addresses an allowed hostname actually resolves to, not just the name.

  • Built-in check: a hostname that resolves only to loopback, unspecified, link-local, multicast, broadcast or cloud-metadata addresses (for example 100.100.100.200, 168.63.129.16, fd00:ec2::/32), or to this machine's own addresses, is refused with the error ERR_SRT_RESOLVED_ADDRESS_DENIED. The proxy answers with HTTP 403 and the header X-Proxy-Error: blocked-by-sandbox-runtime.
  • Exception: such an address can still be reached when its IP literal is itself listed in allowedDomains.
  • New setting deniedResolvedAddresses: extra IP addresses or CIDR ranges (IPv4 or IPv6, unbracketed) that an allowed hostname must not resolve to, checked alongside the built-in set. A name that resolves only into them is refused as "a listed address".
  • Bad entries are rejected with "Invalid IP address or CIDR range. Use an IPv4/IPv6 literal or CIDR ...".
  • The settings schema says this check is not applied to connections routed through parentProxy or mitmProxy.

Why

Without this, an allowed domain whose DNS answer points at an internal address, such as a cloud metadata service, could be used to reach that address from inside the sandbox. Administrators can now add their own internal ranges to the refused set. A command that relied on an allowed name resolving to a local or internal address will now be refused unless that IP is itself allowed.

Read from
Names in the bundledeniedResolvedAddresses
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether this setting can be set in the sandbox section of settings.json, rather than only inside the sandbox's own configuration, is not…

See this entry in the whole of v2.1.284 →

Feedback