Server-Side Request Forgery (SSRF)
A vulnerability in which an attacker makes a server send requests to a destination of the attacker's choosing, often reaching internal services or cloud metadata endpoints that are not directly exposed to the internet.
SSRF occurs when an application fetches a remote resource based on a user-supplied URL or host name, as in webhooks, file imports, image previews or PDF generators, without validating the destination. Because the request originates from the server, it can reach internal administration interfaces, databases and services behind the firewall, or use alternative URL schemes where the client library supports them.
SSRF became a major concern with cloud adoption. Cloud virtual machines can query an instance metadata service at a link-local address that may return temporary credentials, and SSRF has been used to obtain such credentials in publicly reported breaches. SSRF was added as its own category in the OWASP Top 10 2021 and is catalogued as CWE-918. Microservice architectures, in which services trust internal network calls, increase the potential impact.
Defences include validating destinations against an allow-list, resolving host names and blocking private and link-local address ranges, disabling unused URL schemes and redirects, and running fetch functions in network segments with restricted outbound access. Cloud providers offer hardened metadata services, such as AWS IMDSv2 with session tokens, that make exploitation harder. Deny-lists alone are easily bypassed through alternative encodings and DNS tricks.
Key points
- The server, not the attacker, sends the request, bypassing network boundaries.
- Cloud instance metadata endpoints are a frequent SSRF target.
- Added as its own category in the OWASP Top 10 2021; catalogued as CWE-918.
- Allow-list validation and restricted egress are more reliable than deny-lists.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.