#vulns.co
/
mcp by GKData.io

← Back to OWASP

Server-Side Request Forgery (SSRF)

The app fetches a user-supplied URL, letting you reach internal services and cloud metadata.

OWASP rank: 10

Practical checks

  • Find URL-fetching features (webhooks, previews, imports)
  • Set up OOB detection for blind SSRF
  • Target localhost, link-local, and cloud metadata
  • Bypass filters with alternate encodings/redirects

Useful tools

Open the related playbook

← Back to OWASP