n8n 3.0 SSRF blocklist adds 100.64.0.0/10: Sume webhook paths
n8n 3.0 adds 100.64.0.0/10 to its SSRF blocklist. Sume is public HTTPS, so calls are fine, but webhook URLs must be public for Sume to reach them.

Calls from n8n to Sume's public API are unaffected by n8n 3.0's wider SSRF blocklist, but anything that tries to reach an address in 100.64.0.0/10 will now be blocked. The 3.0 breaking-changes page says the blocklist now includes that range. The reverse direction needs a check too: Sume only delivers webhooks to a public HTTPS URL.
What changes in n8n 3.0
| Item | Change |
|---|---|
| SSRF blocklist | Now includes 100.64.0.0/10 |
| N8N_RUNNERS_TASK_TIMEOUT | Default 300 s to 60 s |
| Legacy HTTP Request Tool | Removed |
| OFFLOAD_MANUAL_EXECUTIONS_TO_WORKERS | Removed |
Outbound to Sume
https://api.sume.com/v1 and https://mcp.sume.com/mcp are public hosts, so the HTTP Request node reaches them as before. If you route through an internal proxy that resolves into the newly blocked range, calls would be refused by n8n before leaving. Check the proxy address.
Inbound from Sume
Sume requires a public HTTPS webhook URL and does not follow redirects. Each attempt has a 10 second timeout, with up to 10 attempts. A self-hosted n8n whose Webhook node is reachable only on a private overlay network cannot receive these. Expose the Webhook path through a public HTTPS endpoint, then verify the signature in the first node after it.
- Compute HMAC-SHA256 over
<timestamp>.<raw_body>usingSUME_COM_WEBHOOK_SIGNING_SECRET. - Compare to each
sume-v1=entry in the signature header. - Dedupe on
job_id, orrun_idfor run events.
Quick validation
After upgrading, send POST /v1/webhooks/test-deliveries to your n8n webhook URL. If it arrives, your path is public. If a real delivery was missed, POST /v1/jobs/{id}/webhook/redeliver with jobs:write resends it. Polling /status is the backup.
Sources
Related posts
More in Integrations
- n8n Data table as a Sume job ledger: the 200 MiB default limit
Store each Sume job id in an n8n Data table and upsert it when the webhook arrives. The default cap is 200 MiB per instance, and a full table errors inserts.
- n8n Execution Data node: find a run by its Sume job id
Save the Sume job id with n8n's Execution Data node and you can search the Executions list by it. Keys cap at 50 characters, values at 512, plan limits apply.
- n8n Form Trigger: Respond When and a long Sume video job
n8n's Form Trigger can answer on submit or when the workflow finishes. For a Sume video job that runs minutes, answer on submit and deliver the video later.
- n8n payload limit 16 MiB: pass Sume artifact URLs, not video bytes
n8n caps webhook payloads at 16 MiB and form-data files at 200 MiB. A Sume callback is small JSON with media URLs, so keep the video out of the payload.
Written by Sume