Issue search
Which component is affected?
Prowler CLI/SDK
Cloud Provider (if applicable)
GCP
Steps to Reproduce
- In a GCP project, create an ingress firewall rule allowing tcp:22 (or tcp:3389) with source range ::/0
- Run: prowler gcp --check compute_firewall_ssh_access_from_the_internet_allowed compute_firewall_rdp_access_from_the_internet_allowed
- The rule is reported as PASS
Expected behavior
The rule is reported as FAIL.
::/0 is the IPv6 equivalent of 0.0.0.0/0 and exposes SSH/RDP to the entire IPv6 internet.
Actual Result with Screenshots or Logs
PASS. Both checks decide internet exposure with "0.0.0.0/0" in firewall.source_ranges, so IPv6 open ranges are never matched:
- prowler/providers/gcp/services/compute/compute_firewall_ssh_access_from_the_internet_allowed/compute_firewall_ssh_access_from_the_internet_allowed.py
- prowler/providers/gcp/services/compute/compute_firewall_rdp_access_from_the_internet_allowed/compute_firewall_rdp_access_from_the_internet_allowed.py
Found by reading the code and confirmed with a unit test (firewall with source_ranges=["::/0"] allowing tcp:22 returns PASS).
How did you install Prowler?
Cloning the repository from github.com (git clone)
Environment Resource
Workstation
OS used
MacOS
Prowler version
5.44.0
Python version
3.13.8
Pip version
N/A (uv-managed virtualenv, no pip)
Context
Other providers already treat ::/0 as public: Alibaba Cloud's is_public_cidr and StackIT's is_unrestricted both check ("0.0.0.0/0", "::/0"). The GCP checks should be consistent with them.
Issue search
Which component is affected?
Prowler CLI/SDK
Cloud Provider (if applicable)
GCP
Steps to Reproduce
Expected behavior
The rule is reported as FAIL.
::/0 is the IPv6 equivalent of 0.0.0.0/0 and exposes SSH/RDP to the entire IPv6 internet.
Actual Result with Screenshots or Logs
PASS. Both checks decide internet exposure with
"0.0.0.0/0" in firewall.source_ranges, so IPv6 open ranges are never matched:Found by reading the code and confirmed with a unit test (firewall with source_ranges=["::/0"] allowing tcp:22 returns PASS).
How did you install Prowler?
Cloning the repository from github.com (git clone)
Environment Resource
Workstation
OS used
MacOS
Prowler version
5.44.0
Python version
3.13.8
Pip version
N/A (uv-managed virtualenv, no pip)
Context
Other providers already treat ::/0 as public: Alibaba Cloud's is_public_cidr and StackIT's is_unrestricted both check ("0.0.0.0/0", "::/0"). The GCP checks should be consistent with them.