Back to Glossary

What is Server-Side Request Forgery (SSRF)?

Definition

A flaw that allows an attacker to force a server to make unauthorized requests to internal or external resources.

Security Impact

Exposes internal microservices, AWS IMDS metadata (stealing IAM keys), and allows internal network scanning.

How to Remediate

Validate all outbound URLs against a strict allowlist. Block access to internal IP ranges (e.g., 169.254.169.254, 10.0.0.0/8).

Want to automatically detect and block Server-Side Request Forgery (SSRF) vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →