NVIDIA-NeMo / NVIDIA-NeMo/Guardrails
bug: require TLS for remote jailbreak detection NIM endpoints
@Pouyanpi is already working on this.
Since Jul 22, 2026.
- Dominant language
- Python
- Stars
- 7.2k
- Forks
- 843
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 25
Description
Did you check docs and existing issues?
- I have read all the NeMo-Guardrails docs (not verified; this is a code-review follow-up)
- I have updated the package to the latest version before submitting this issue (not applicable; identified on an unmerged pull request)
- I have used the develop branch (the affected change targets
develop) - I have searched the existing issues of NeMo-Guardrails (not verified by this report)
Python version (python --version)
Not applicable — this is a static configuration-validation issue identified during review.
Operating system/version
Not applicable — the issue is independent of the operating system.
NeMo-Guardrails version (if you must use a specific version and not the latest)
Unreleased change in PR #2185.
Describe the bug
JailbreakDetectionConfig allows a remote nim_base_url using http://, and migrate_deprecated_fields() constructs an http:// URL from deprecated nim_url/nim_port inputs. The jailbreak detection action can use get_api_key() for requests to this endpoint, so a remote deployment using HTTP can transmit the NIM API credential without transport encryption.
Affected area: nemoguardrails/library/jailbreak_detection/rail_config.py, specifically JailbreakDetectionConfig.migrate_deprecated_fields() and JailbreakDetectionConfig.validate_urls().
This is intentionally tracked separately because it is pre-existing and outside the scope of PR #2185.
Related PR: https://github.com/NVIDIA-NeMo/Guardrails/pull/2185
Related review comment: https://github.com/NVIDIA-NeMo/Guardrails/pull/2185#discussion_r3628609526
Requested by: @Pouyanpi
Steps To Reproduce
- Configure
JailbreakDetectionConfig(nim_base_url="http://remote.example/v1", api_key_env_var="NIM_API_KEY"); the current URL validation accepts it. - Alternatively, configure the deprecated
nim_url="remote.example"(and optionallynim_port); the migration produceshttp://remote.example:8000/v1. - Configure an API key directly or through
api_key_env_var. - Use the remote NIM endpoint for jailbreak detection; the request may include the API credential over cleartext HTTP.
Expected Behavior
Remote NIM endpoints must use https://. Plain http:// may remain supported only for loopback/local development endpoints. Deprecated nim_url/nim_port migration must not construct a cleartext remote URL.
Acceptance criteria:
- Direct remote
http://values fornim_base_urlare rejected with a clear validation error. - Remote deprecated
nim_url/nim_portconfigurations migrate to an HTTPS URL or are rejected with a migration message that requires an HTTPSnim_base_url. - Loopback HTTP endpoints remain supported where intended for local development.
- Existing URL-scheme validation remains in place.
- Tests cover accepted loopback HTTP, accepted remote HTTPS, rejected remote HTTP, and deprecated-field migration behavior.
Actual Behavior
The current validation accepts both http:// and https:// for nim_base_url. When the deprecated nim_url field is used, migration unconditionally generates an http:// endpoint, including for remote hosts. This can expose an API key in transit.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.