$npx skillfedfor your agent

safehttpx

A small Python library created to help developers protect their applications from Server Side Request Forgery (SSRF) attacks.

With conditionsPyPI SecurityReleased Oct 20256.1M downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — safehttpx-0.1.7-py3-none-any.whl
v0.1.7 · released 2025-10-24 · Python >3.9 · 1 runtime deps: httpx

Yes, if you need SSRF protection and are already using async HTTP in Python >3.9. The library is lightweight, permissively licensed, and battle-tested in Gradio. The aging maintenance status (no release in 294 days) is a minor concern but not a blocker if the current version meets your needs; no known vulnerabilities are recorded. Install it if SSRF is a real threat in your application; skip it if you are not accepting untrusted URLs or are not using async code.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python >3.9 and an asyncio event loop; the get() method is async-only and will reject requests to private/reserved IP ranges by default.
  • Low friction: pure Python wheel with a single runtime dependency (httpx).
  • Maintenance status is aging—last commit was 2025-10-24 and the project has not released a new version in 294 days, though the repository remains active and unarchived.

License · maintenance · safety

permissive license (permissive) — MIT license (permissive). You may use, modify, and distribute this package freely, including in commercial applications, provided you retain the license notice.

last release 2025-10-24 (294 days) · last repo commit 2025-10-24 · 72 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,067,160 downloads/mo, #1,974 on PyPI

Verify before relying

import asyncio
import safehttpx as sh

await sh.get("https://huggingface.co")
# or in a script:
asyncio.run(sh.get("https://huggingface.co"))
  • Whether Google DNS is always reachable or if there is a fallback mechanism for DNS resolution.
  • Performance overhead of DNS validation on each request compared to standard httpx.
  • Whether the whitelist feature supports wildcards or only exact domain matches.
  • Specific DNS rebinding attack scenarios the library defends against beyond basic validation.
Same gist for agents: .md · .json

What it is and what it does

safehttpx is an async HTTP client wrapper that adds SSRF attack protection on top of httpx. It validates URLs against public DNS before making requests and implements defenses against DNS rebinding attacks, which can trick applications into accessing internal services. The library rejects requests to private IP ranges (like 127.0.0.1) by default, but allows whitelisting of specific domains when needed—for instance, if your infrastructure uses DNS splitting to serve internal and external addresses differently.

The package is a thin, low-friction layer: it depends only on httpx and comes as a pure Python wheel. It was created following a security audit of Gradio and is now used in production there. The async-only API means you must structure code around asyncio, either by using it in an event-loop-aware environment (Jupyter, IPython) or by wrapping calls in asyncio.run() in standard scripts.

Use it for

  • Protect web services that fetch user-supplied URLs (e.g., link previews, webhook handlers) from SSRF attacks.
  • Prevent attackers from using your server to scan internal networks or access cloud metadata services.
  • Safely make HTTP requests in multi-tenant or untrusted-input scenarios where URL validation is critical.
  • Block DNS rebinding attacks that attempt to redirect public domains to internal IP addresses mid-request.
  • Whitelist trusted internal domains while still validating external URLs in hybrid network architectures.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need SSRF protection and are already using async HTTP in Python >3.9.

The library is lightweight, permissively licensed, and battle-tested in Gradio. The aging maintenance status (no release in 294 days) is a minor concern but not a blocker if the current version meets your needs; no known vulnerabilities are recorded. Install it if SSRF is a real threat in your application; skip it if you are not accepting untrusted URLs or are not using async code.

Install

safehttpx on PyPI

Before you install

Low friction: pure Python wheel with a single runtime dependency (httpx). Maintenance status is aging—last commit was 2025-10-24 and the project has not released a new version in 294 days, though the repository remains active and unarchived.

Requires Python >3.9 and an asyncio event loop; the get() method is async-only and will reject requests to private/reserved IP ranges by default.

License in practice

MIT license (permissive). You may use, modify, and distribute this package freely, including in commercial applications, provided you retain the license notice.

Quickstart

import asyncio
import safehttpx as sh

await sh.get("https://huggingface.co")
# or in a script:
asyncio.run(sh.get("https://huggingface.co"))

Verify before relying

  • Whether Google DNS is always reachable or if there is a fallback mechanism for DNS resolution.
  • Performance overhead of DNS validation on each request compared to standard httpx.
  • Whether the whitelist feature supports wildcards or only exact domain matches.
  • Specific DNS rebinding attack scenarios the library defends against beyond basic validation.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
httpx
MaintenanceAging 294 days since the last release
Last repo commit
First released
Downloads6,067,160 / month, #1,974 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3

Evidence: safehttpx-0.1.7-py3-none-any.whl

Tags

Capabilities
SSRF protectionDNS validation HTTPDNS rebinding defensesafe async HTTP requestsserver-side request forgery preventioninternal network request blockingasync HTTP with DNS checks
Topics
ssrf-protectionasync-httpdns-validation

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “SSRF protection”

  • safehttpxWraps httpx.AsyncClient.get() with DNS validation and DNS rebinding…
  • advocateAdvocate wraps the requests library to prevent SSRF attacks by…
  • requests-hardenedWraps the requests library to enforce security defaults and block…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also advocate · requests-hardened · asgi-csrf · flask-talisman · fastapi-csrf-protect · dnstwist · proxy.py · urllib3-future · httpx-socks · PySocks