Glossary Security

SSRF

SSRF (server-side request forgery) is a vulnerability that lets an attacker make a server send requests to places it should not, such as internal systems.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Features that fetch a user-supplied URL, such as link previews or webhooks, can be aimed at localhost, private network ranges or cloud metadata services that the attacker cannot reach directly. Defences: resolve the hostname first and refuse private and loopback addresses, allow only needed schemes, and do not follow redirects blindly.

See also

  • Glossary Localhost
    Localhost is the standard name for "this computer": a loopback address that sends network traffic back to your own machine.
  • Glossary Redirect
    A redirect is a server response that sends the browser to a different URL, using a 3xx status code and a Location header.
  • Glossary Vulnerability
    A vulnerability is a weakness in software, hardware or a process that an attacker could exploit to do something unintended.
AdSense Placeholder
Slot: footer_leaderboard