SSRF
Server-side request forgery
Persuading a server to make a network request on your behalf, to somewhere you could not reach yourself.
A tool that accepts a URL and fetches it is an SSRF risk unless it validates where it is being pointed. The classic target is an internal address that is unreachable from outside but reachable from the server, including cloud metadata endpoints that hand out credentials.
An independent scan of more than seven thousand public MCP servers in 2026 found that over a third of URL-accepting servers did not validate outbound requests.
It is the most common serious finding in this category by a wide margin, and it is entirely preventable with an allow-list.
Blocking a list of bad addresses instead of allowing a list of good ones. Denylists are defeated by redirects, alternative encodings and DNS that resolves differently the second time.
Related terms
See SSRF on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue