API7:2023: Server Side Request Forgery (SSRF)
API fetches a remote resource without validating the user-supplied URL, allowing attackers to make the server reach internal/cloud-metadata endpoints.
How it's found
Identified by injecting internal and cloud-metadata URLs into every URL-accepting parameter to confirm the server fetches attacker-controlled destinations.
Standards mapping
- CWE
- CWE-918
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Server-Side Request Forgery (SSRF) using Nuclei and OWASP ZAP, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Tools: Nuclei, OWASP ZAP
Frequently asked questions
What is API7:2023 Server Side Request Forgery (SSRF)?
API fetches a remote resource without validating the user-supplied URL, allowing attackers to make the server reach internal/cloud-metadata endpoints.
How do you find Server Side Request Forgery (SSRF)?
Identified by injecting internal and cloud-metadata URLs into every URL-accepting parameter to confirm the server fetches attacker-controlled destinations.
Which CWEs map to API7:2023?
API7:2023 maps to CWE-918.
Does TurboPentest test for Server Side Request Forgery (SSRF)?
TurboPentest's automated black-box pentest actively probes for Server-Side Request Forgery (SSRF) using Nuclei and OWASP ZAP, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Related OWASP categories
- OWASP API Security Top 10API1:2023: Broken Object Level Authorization
- OWASP API Security Top 10API2:2023: Broken Authentication
- OWASP API Security Top 10API3:2023: Broken Object Property Level Authorization
- OWASP API Security Top 10API4:2023: Unrestricted Resource Consumption
- OWASP API Security Top 10API5:2023: Broken Function Level Authorization
- OWASP API Security Top 10API6:2023: Unrestricted Access to Sensitive Business Flows
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest