Skip to content

Bump github.com/elazarl/goproxy from 1.9.0 to 1.9.1 - #271

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/elazarl/goproxy-1.9.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/elazarl/goproxy-1.9.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/elazarl/goproxy from 1.9.0 to 1.9.1.

Release notes

Sourced from github.com/elazarl/goproxy's releases.

v1.9.1

What's Changed

New Contributors

Full Changelog: elazarl/goproxy@v1.9.0...v1.9.1

Commits
  • e540bd6 fix(mitm): never frame bodiless responses as chunked (#797)
  • 2b17647 Echo client HTTP version in CONNECT tunnel reply (#802) (#804)
  • 4c85e93 Fix: normalize req.URL.Host in MITM by prioritizing inner Host header (#799)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/elazarl/goproxy](https://github.com/elazarl/goproxy) from 1.9.0 to 1.9.1.
- [Release notes](https://github.com/elazarl/goproxy/releases)
- [Commits](elazarl/goproxy@v1.9.0...v1.9.1)

---
updated-dependencies:
- dependency-name: github.com/elazarl/goproxy
  dependency-version: 1.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

@jeffwidman jeffwidman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Build failure is a deterministic compatibility regression from goproxy 1.9.1, specifically elazarl/goproxy#799. For HTTPS requests inside a CONNECT tunnel, it now reconstructs req.URL using the inner Host header instead of the original CONNECT destination. This proxy relies on req.URL.Host retaining the actual destination while the potentially spoofed req.Host is normalized and checked separately.

As a result:

  • Requests to metadata.google.internal with inner Host: example.com bypass the metadata block: both :443 and :8443 cases expected 403 but received 404.
  • A local request with inner Host: api.dependabot.example is routed to that hostname, fails DNS lookup, and returns EOF.
  • A local request with inner Host: metadata.google.internal is incorrectly blocked with 403 instead of reaching the local upstream with 200.

A rerun will not resolve this. This should remain on 1.9.0 unless the proxy is changed to preserve and validate the CONNECT destination independently of the inner Host header.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant