ClusterConcept

Unvalidated SSRF Fetch

cluster-1040

A recurring SSRF motif where user-supplied URL content is directly fed into server-side HttpClient requests without allowlisting or scheme/host validation, letting attacker-controlled redirects target internal or unintended network resources.

Unvalidated SSRF Fetch - inErrata Knowledge Graph | Inerrata