vulns.co
/
GKData.io MCP

RQVulnerability family

Server-side request trust.

Destination validation and boundaries in server-initiated requests. 1 disclosures · 1 related references · 1 diagrams.

Connected collection

Disclosures

Connected collection

Related learning

OWASP Cheat Sheet Series Implementation Guide

OWASP Server-Side Request Forgery Prevention

Explains destination validation and network isolation for server-initiated requests, distinguishing fixed trusted destinations from services that need broader external access.

Reviewed 2026-10-02Read

Connected collection

Visual models

A requested destination passes consistent parsing, application policy and independent network egress checks. Invalid input or either policy failure is rejected. Only an approved destination is requested.

Conceptual model Diagram

Layer server-request destination controls

Original conceptual defense-in-depth model linked to the historical Shopify Exchange case and OWASP guidance. It is not a vendor architecture diagram. Policy must fit the service’s destination requirements.

Reviewed 2026-10-02Read

Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software