Ssrf Prevention

Server-Side Request Forgery: allowlisting the destination of a server-side fetch, when re-resolution between check and connect matters, redirect and scheme bypasses, parsers that fetch on their own (XXE, SVG, HTML-to-PDF), cloud metadata, and keeping the response from becoming an oracle. Use when fetching a client-supplied URL, wiring webhooks, image proxies, PDF or preview renderers, or reviewing any HTTP-client wrapper.

ShieldNet-360 906c5a1 6 files · 27.6 KB Updated

File contents

ShieldNet-360/secure-vibe/tree/main/skills/ssrf-prevention commit 906c5a1f8a

Frequently asked questions

npx skillmds@latest add shieldnet-360/ssrf-prevention