Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Security findings

SSRF

Server-side request forgery

Persuading a server to make a network request on your behalf, to somewhere you could not reach yourself.

A tool that accepts a URL and fetches it is an SSRF risk unless it validates where it is being pointed. The classic target is an internal address that is unreachable from outside but reachable from the server, including cloud metadata endpoints that hand out credentials.

An independent scan of more than seven thousand public MCP servers in 2026 found that over a third of URL-accepting servers did not validate outbound requests.

Why it matters

It is the most common serious finding in this category by a wide margin, and it is entirely preventable with an allow-list.

The mistake everyone makes

Blocking a list of bad addresses instead of allowing a list of good ones. Denylists are defeated by redirects, alternative encodings and DNS that resolves differently the second time.

Related terms

Egress allow-list
An explicit list of the hosts a piece of software is permitted to contact.
Least privilege
Granting the narrowest access that makes the job possible, and nothing beyond it.
Finding
One issue raised by verification, with a severity and a mapping to a standard weakness class.
Previous
Shipped credential
Next
Static analysis

See SSRF on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue