Back to Glossary
What is Server-Side Request Forgery (SSRF)?
Definition
A flaw that allows an attacker to force a server to make unauthorized requests to internal or external resources.
Security Impact
Exposes internal microservices, AWS IMDS metadata (stealing IAM keys), and allows internal network scanning.
How to Remediate
Validate all outbound URLs against a strict allowlist. Block access to internal IP ranges (e.g., 169.254.169.254, 10.0.0.0/8).
Want to automatically detect and block Server-Side Request Forgery (SSRF) vulnerabilities in your CI/CD pipeline?
Start scanning with Bryxe