Server-Side Request Forgery
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
An attacker can use SSRF vulnerabilities to probe your internal network.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Harmful
What is server-side request forgery (SSRF)?
Server-side request forgery (SSRF) is a request forgery attack in which an attacker causes your server to make an HTTP request to a destination they choose, usually by supplying a URL the server fetches. Because the request originates inside your network, it can reach internal services and cloud metadata endpoints that are hidden from the internet.
What you'll learn
- How a URL-fetching feature lets attackers send requests from your server
- Why requests from inside your network can reach internal services
- How to validate and restrict the URLs your server will fetch
Where this lesson counts
OWASP Top 10
Users act outside their intended permissions, exposing or modifying data they should never reach. Now includes SSRF.
SSRF was folded into Broken Access Control in the 2025 list.
Learn more about A01This lesson includes
-
Server-Side Request Forgery lab
A social site fetches a preview for every link its users share. See how an attacker uses that feature to make your server send requests of their choosing: flooding a third party from behind your address, or probing private IP addresses on your internal network.
-
How to prevent Server-Side Request Forgery
The prevention guide covers five approaches:
- Construct The Domains Of URLs On The Server
- Disable External Validation URLs
- Only Make Outgoing HTTP Calls On Behalf of Real Users
- Validate The URLs You Do Access
- Keep A Blocklist
-
Server-Side Request Forgery quiz
Three questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
Host Header Poisoning
It's dangerous to rely on the value supplied in the Host header of an HTTP request.
Open Redirects
Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.
XML External Entities
Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.
Broken Access Control
All resources on your site need to have access control implemented, even if they aren't intended to be discoverable by a user.