safehttpx
A small Python library created to help developers protect their applications from Server Side Request Forgery (SSRF) attacks.
Decision gist · record as of 2026-08-14
Yes, if you need SSRF protection and are already using async HTTP in Python >3.9. The library is lightweight, permissively licensed, and battle-tested in Gradio. The aging maintenance status (no release in 294 days) is a minor concern but not a blocker if the current version meets your needs; no known vulnerabilities are recorded. Install it if SSRF is a real threat in your application; skip it if you are not accepting untrusted URLs or are not using async code.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >3.9 and an asyncio event loop; the get() method is async-only and will reject requests to private/reserved IP ranges by default.
- Low friction: pure Python wheel with a single runtime dependency (httpx).
- Maintenance status is aging—last commit was 2025-10-24 and the project has not released a new version in 294 days, though the repository remains active and unarchived.
License · maintenance · safety
permissive license (permissive) — MIT license (permissive). You may use, modify, and distribute this package freely, including in commercial applications, provided you retain the license notice.
last release 2025-10-24 (294 days) · last repo commit 2025-10-24 · 72 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,067,160 downloads/mo, #1,974 on PyPI
Alternatives
Verify before relying
import asyncio
import safehttpx as sh
await sh.get("https://huggingface.co")
# or in a script:
asyncio.run(sh.get("https://huggingface.co"))- Whether Google DNS is always reachable or if there is a fallback mechanism for DNS resolution.
- Performance overhead of DNS validation on each request compared to standard httpx.
- Whether the whitelist feature supports wildcards or only exact domain matches.
- Specific DNS rebinding attack scenarios the library defends against beyond basic validation.
What it is and what it does
safehttpx is an async HTTP client wrapper that adds SSRF attack protection on top of httpx. It validates URLs against public DNS before making requests and implements defenses against DNS rebinding attacks, which can trick applications into accessing internal services. The library rejects requests to private IP ranges (like 127.0.0.1) by default, but allows whitelisting of specific domains when needed—for instance, if your infrastructure uses DNS splitting to serve internal and external addresses differently.
The package is a thin, low-friction layer: it depends only on httpx and comes as a pure Python wheel. It was created following a security audit of Gradio and is now used in production there. The async-only API means you must structure code around asyncio, either by using it in an event-loop-aware environment (Jupyter, IPython) or by wrapping calls in asyncio.run() in standard scripts.
Use it for
- Protect web services that fetch user-supplied URLs (e.g., link previews, webhook handlers) from SSRF attacks.
- Prevent attackers from using your server to scan internal networks or access cloud metadata services.
- Safely make HTTP requests in multi-tenant or untrusted-input scenarios where URL validation is critical.
- Block DNS rebinding attacks that attempt to redirect public domains to internal IP addresses mid-request.
- Whitelist trusted internal domains while still validating external URLs in hybrid network architectures.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need SSRF protection and are already using async HTTP in Python >3.9.
The library is lightweight, permissively licensed, and battle-tested in Gradio. The aging maintenance status (no release in 294 days) is a minor concern but not a blocker if the current version meets your needs; no known vulnerabilities are recorded. Install it if SSRF is a real threat in your application; skip it if you are not accepting untrusted URLs or are not using async code.
Install
safehttpx on PyPI
Before you install
Low friction: pure Python wheel with a single runtime dependency (httpx). Maintenance status is aging—last commit was 2025-10-24 and the project has not released a new version in 294 days, though the repository remains active and unarchived.
Requires Python >3.9 and an asyncio event loop; the get() method is async-only and will reject requests to private/reserved IP ranges by default.
License in practice
MIT license (permissive). You may use, modify, and distribute this package freely, including in commercial applications, provided you retain the license notice.
Quickstart
import asyncio
import safehttpx as sh
await sh.get("https://huggingface.co")
# or in a script:
asyncio.run(sh.get("https://huggingface.co"))
Verify before relying
- Whether Google DNS is always reachable or if there is a fallback mechanism for DNS resolution.
- Performance overhead of DNS validation on each request compared to standard httpx.
- Whether the whitelist feature supports wildcards or only exact domain matches.
- Specific DNS rebinding attack scenarios the library defends against beyond basic validation.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagehttpx |
| Maintenance | Aging 294 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 6,067,160 / month, #1,974 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: safehttpx-0.1.7-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “SSRF protection”
- safehttpxWraps httpx.AsyncClient.get() with DNS validation and DNS rebinding…
- advocateAdvocate wraps the requests library to prevent SSRF attacks by…
- requests-hardenedWraps the requests library to enforce security defaults and block…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also advocate · requests-hardened · asgi-csrf · flask-talisman · fastapi-csrf-protect · dnstwist · proxy.py · urllib3-future · httpx-socks · PySocks