PAC-C007 · wrong-rfc1918-mask

RFC 1918 range with the wrong mask

medium · Correctness · Top 20 #17

172.16.0.0 with mask 255.255.0.0 covers only 172.16.x.x. The private block is 172.16.0.0/12 (mask 255.240.0.0), i.e. 172.16.0.0 to 172.31.255.255; the /16 misses fifteen sixteenths of it.

Why it matters

RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The middle block is the one that gets written wrong: /16 instead of /12. With mask 255.255.0.0 the host 172.20.0.5 is outside the match and takes the default route (lab, 2026-05-20). The symptom is a subset of internal addresses going to the proxy, which may not route to them. A mask narrower than the canonical one with the canonical base address is almost always a mistake; a deliberately narrower internal range normally starts at a different base.

How to fix

Use 255.240.0.0 for 172.16.0.0, 255.0.0.0 for 10.0.0.0 and 255.255.0.0 for 192.168.0.0.

Examples

Bad

function FindProxyForURL(url, host) {
  if (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "172.16.0.0", "255.255.0.0")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "172.16.0.0", "255.240.0.0")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References