<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — SSRF</title>
  <link>https://appsec.fyi/ssrf.html</link>
  <description>Curated SSRF resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/ssrf.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Sun, 12 Apr 2026 04:12:19 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>Flowise is affected by a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-31829) in its HTTP Node potentially allowing internal network access. Investigate network segmentation and outbound request filtering. #Flowise #SSRF #infosec pulsepatch.io/posts/cve-2026</title>
    <link>https://x.com/pulsepatchio/status/2043165028501647442</link>
    <guid isPermaLink="true">https://x.com/pulsepatchio/status/2043165028501647442</guid>
    <description>`Flowise` is affected by a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-31829) in its HTTP Node, potentially allowing internal network access. Investigate network segmentation and outbou...</description>
    <category>SSRF</category>
    <pubDate>Sun, 12 Apr 2026 03:23:20 +0000</pubDate>
  </item>
  <item>
    <title>Gus March-Phillipps led the SSRF into the darkness with nerves of steel. Gone but not forgotten RiP Warriors. Come follow in their footsteps. soeexpeditions.com soeexpeditions.com/ssrf-jersey-1 #ssrf #anderslassen #commando #ww2 pic.x.com/79jvm5XRbx</title>
    <link>https://x.com/SOE_Expeditions/status/2042876556788322507</link>
    <guid isPermaLink="true">https://x.com/SOE_Expeditions/status/2042876556788322507</guid>
    <description>Gus March-Phillipps led the SSRF into the darkness with nerves of steel. Gone but not forgotten RiP Warriors. Come follow in their footsteps. soeexpeditions.com soeexpeditions.com/ssrf-jersey-1 #ssrf ...</description>
    <category>SSRF</category>
    <pubDate>Sat, 11 Apr 2026 08:08:29 +0000</pubDate>
  </item>
  <item>
    <title>A NO_PROXY hostname normalization bypass (CVE-2025-62718) in Axios could lead to SSRF. Implement strict input validation and monitor for patches. #Axios #SSRF #infosec pulsepatch.io/posts/cve-2025</title>
    <link>https://x.com/pulsepatchio/status/2042796432785043871</link>
    <guid isPermaLink="true">https://x.com/pulsepatchio/status/2042796432785043871</guid>
    <description>A NO_PROXY hostname normalization bypass (CVE-2025-62718) in `Axios` could lead to SSRF. Implement strict input validation and monitor for patches. #Axios #SSRF #infosec pulsepatch.io/posts/cve-2025… ...</description>
    <category>SSRF</category>
    <pubDate>Sat, 11 Apr 2026 03:03:37 +0000</pubDate>
  </item>
  <item>
    <title>Anders Lassen: Legend of the SSRF. Every mission was a dance with destiny in the Channel Islands. Gone but not forgotten RiP Warriors. Walk in their footsteps: soeexpeditions.com/ssrf-jersey-1 soeexpeditions.com #ssrf #anderslassen #commando #ww2 pic.x.com/580HdJZaJt</title>
    <link>https://x.com/SOE_Expeditions/status/2042514343737082234</link>
    <guid isPermaLink="true">https://x.com/SOE_Expeditions/status/2042514343737082234</guid>
    <description>Anders Lassen: Legend of the SSRF. Every mission was a dance with destiny in the Channel Islands. Gone but not forgotten RiP Warriors. Walk in their footsteps: soeexpeditions.com/ssrf-jersey-1 soeexpe...</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 08:18:40 +0000</pubDate>
  </item>
  <item>
    <title>HackerOne: SSRF in Exchange Leads to ROOT (Shopify)</title>
    <link>https://hackerone.com/reports/341876</link>
    <guid isPermaLink="true">https://hackerone.com/reports/341876</guid>
    <description>HackerOne: SSRF in Exchange Leads to ROOT (Shopify)</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:39 +0000</pubDate>
  </item>
  <item>
    <title>DEF CON 27: Owning the Clout Through SSRF and PDF Generators</title>
    <link>https://media.defcon.org/DEF%20CON%2027/DEF%20CON%2027%20presentations/DEFCON-27-Ben-Sadeghipour-Owning-the-clout-through-SSRF-and-PDF-generators.pdf</link>
    <guid isPermaLink="true">https://media.defcon.org/DEF%20CON%2027/DEF%20CON%2027%20presentations/DEFCON-27-Ben-Sadeghipour-Owning-the-clout-through-SSRF-and-PDF-generators.pdf</guid>
    <description>DEF CON 27: Owning the Clout Through SSRF and PDF Generators</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:38 +0000</pubDate>
  </item>
  <item>
    <title>PentesterLab: SSRF in PDF Generation</title>
    <link>https://pentesterlab.com/exercises/pdf_ssrf</link>
    <guid isPermaLink="true">https://pentesterlab.com/exercises/pdf_ssrf</guid>
    <description>PentesterLab: SSRF in PDF Generation</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:37 +0000</pubDate>
  </item>
  <item>
    <title>The Ultimate Sink for SSRFs: HTML To PDF Converters</title>
    <link>https://medium.com/@rkvb/the-ultimate-sink-for-ssrfs-html-to-pdf-converters-353b66398f52</link>
    <guid isPermaLink="true">https://medium.com/@rkvb/the-ultimate-sink-for-ssrfs-html-to-pdf-converters-353b66398f52</guid>
    <description>The Ultimate Sink for SSRFs: HTML To PDF Converters</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:36 +0000</pubDate>
  </item>
  <item>
    <title>SSRF to LFI Payload for PDF Generators (CVE-2024-34112)</title>
    <link>https://www.hoyahaxa.com/2025/01/an-ssrf-to-lfi-payload-for-pdf.html</link>
    <guid isPermaLink="true">https://www.hoyahaxa.com/2025/01/an-ssrf-to-lfi-payload-for-pdf.html</guid>
    <description>SSRF to LFI Payload for PDF Generators (CVE-2024-34112)</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:36 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting PDF Generators: Complete Guide to SSRF</title>
    <link>https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-pdf-generators-a-complete-guide-to-finding-ssrf-vulnerabilities-in-pdf-generators</link>
    <guid isPermaLink="true">https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-pdf-generators-a-complete-guide-to-finding-ssrf-vulnerabilities-in-pdf-generators</guid>
    <description>Exploiting PDF Generators: Complete Guide to SSRF</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:35 +0000</pubDate>
  </item>
  <item>
    <title>Mastering SSRF: Ultra-Extensive Guide</title>
    <link>https://medium.com/@okanyildiz1994/mastering-ssrf-vulnerabilities-an-ultra-extensive-guide-to-understanding-and-mitigating-43aa09a8df08</link>
    <guid isPermaLink="true">https://medium.com/@okanyildiz1994/mastering-ssrf-vulnerabilities-an-ultra-extensive-guide-to-understanding-and-mitigating-43aa09a8df08</guid>
    <description>Mastering SSRF: Ultra-Extensive Guide</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:34 +0000</pubDate>
  </item>
  <item>
    <title>Metabadger: Prevent SSRF via Automated IMDSv2 Upgrades</title>
    <link>https://github.com/salesforce/metabadger</link>
    <guid isPermaLink="true">https://github.com/salesforce/metabadger</guid>
    <description>Metabadger: Prevent SSRF via Automated IMDSv2 Upgrades</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:33 +0000</pubDate>
  </item>
  <item>
    <title>How to Use IMDSv2 for Secure Instance Metadata Access</title>
    <link>https://oneuptime.com/blog/post/2026-02-12-use-imdsv2-for-secure-instance-metadata-access/view</link>
    <guid isPermaLink="true">https://oneuptime.com/blog/post/2026-02-12-use-imdsv2-for-secure-instance-metadata-access/view</guid>
    <description>How to Use IMDSv2 for Secure Instance Metadata Access</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:33 +0000</pubDate>
  </item>
  <item>
    <title>SSRF Cheat Sheet 2025: Exploits, Defenses &amp; Case Studies</title>
    <link>https://zus3c.medium.com/ssrf-cheat-sheet-2025-latest-exploits-defenses-real-world-case-studies-6f028d121455</link>
    <guid isPermaLink="true">https://zus3c.medium.com/ssrf-cheat-sheet-2025-latest-exploits-defenses-real-world-case-studies-6f028d121455</guid>
    <description>SSRF Cheat Sheet 2025: Exploits, Defenses &amp; Case Studies</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:32 +0000</pubDate>
  </item>
  <item>
    <title>AWS Defense in Depth Against SSRF with EC2 IMDS</title>
    <link>https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/</link>
    <guid isPermaLink="true">https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/</guid>
    <description>AWS Defense in Depth Against SSRF with EC2 IMDS</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:31 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2025-51591: SSRF Exploit Targets AWS Instance Metadata Service</title>
    <link>https://cybersecurity88.com/news/cve-2025-51591-new-ssrf-exploit-targets-aws-instance-metadata-service/</link>
    <guid isPermaLink="true">https://cybersecurity88.com/news/cve-2025-51591-new-ssrf-exploit-targets-aws-instance-metadata-service/</guid>
    <description>CVE-2025-51591: SSRF Exploit Targets AWS Instance Metadata Service</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:31 +0000</pubDate>
  </item>
  <item>
    <title>Cloud Penetration Testing: AWS, Azure &amp; GCP Guide (2026)</title>
    <link>https://securitywall.co/blog/cloud-penetration-testing-aws-azure-gcp-guide-2026</link>
    <guid isPermaLink="true">https://securitywall.co/blog/cloud-penetration-testing-aws-azure-gcp-guide-2026</guid>
    <description>Cloud Penetration Testing: AWS, Azure &amp; GCP Guide (2026)</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:30 +0000</pubDate>
  </item>
  <item>
    <title>GCP SSRF on Action Hub Extension - Tenable</title>
    <link>https://www.tenable.com/security/research/tra-2025-45</link>
    <guid isPermaLink="true">https://www.tenable.com/security/research/tra-2025-45</guid>
    <description>GCP SSRF on Action Hub Extension - Tenable</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:29 +0000</pubDate>
  </item>
  <item>
    <title>SSRF Exposes Data of Technology, Industrial and Media Organizations</title>
    <link>https://unit42.paloaltonetworks.com/server-side-request-forgery-exposes-data-of-technology-industrial-and-media-organizations/</link>
    <guid isPermaLink="true">https://unit42.paloaltonetworks.com/server-side-request-forgery-exposes-data-of-technology-industrial-and-media-organizations/</guid>
    <description>SSRF Exposes Data of Technology, Industrial and Media Organizations</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:28 +0000</pubDate>
  </item>
  <item>
    <title>SSRF in the Kubernetes World - Kubernetes Goat</title>
    <link>https://madhuakula.com/kubernetes-goat/docs/scenarios/scenario-3/ssrf-in-the-kubernetes-world/welcome/</link>
    <guid isPermaLink="true">https://madhuakula.com/kubernetes-goat/docs/scenarios/scenario-3/ssrf-in-the-kubernetes-world/welcome/</guid>
    <description>SSRF in the Kubernetes World - Kubernetes Goat</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:28 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting SSRF in Cloud-Only Environments: A Deep Dive</title>
    <link>https://blog.nashtechglobal.com/exploiting-ssrf-in-cloud-only-environments-a-deep-dive/</link>
    <guid isPermaLink="true">https://blog.nashtechglobal.com/exploiting-ssrf-in-cloud-only-environments-a-deep-dive/</guid>
    <description>Exploiting SSRF in Cloud-Only Environments: A Deep Dive</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:27 +0000</pubDate>
  </item>
  <item>
    <title>Private IP Addresses Deep Dive: Security Risks, SSRF, and Exploitation</title>
    <link>https://www.penligent.ai/hackinglabs/private-ip-addresses-deep-dive-security-risks-ssrf-and-modern-exploitation/</link>
    <guid isPermaLink="true">https://www.penligent.ai/hackinglabs/private-ip-addresses-deep-dive-security-risks-ssrf-and-modern-exploitation/</guid>
    <description>Private IP Addresses Deep Dive: Security Risks, SSRF, and Exploitation</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:26 +0000</pubDate>
  </item>
  <item>
    <title>FastGPT Critical SSRF via Unauthenticated HTTP Proxy Endpoint</title>
    <link>https://www.thehackerwire.com/fastgpt-critical-ssrf-via-unauthenticated-http-proxy-endpoint/</link>
    <guid isPermaLink="true">https://www.thehackerwire.com/fastgpt-critical-ssrf-via-unauthenticated-http-proxy-endpoint/</guid>
    <description>FastGPT Critical SSRF via Unauthenticated HTTP Proxy Endpoint</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:25 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-35572: SSRF in ChurchCRM</title>
    <link>https://radar.offseq.com/threat/cve-2026-35572-cwe-918-server-side-request-forgery-9880f733</link>
    <guid isPermaLink="true">https://radar.offseq.com/threat/cve-2026-35572-cwe-918-server-side-request-forgery-9880f733</guid>
    <description>CVE-2026-35572: SSRF in ChurchCRM</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:25 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-34936: SSRF in PraisonAI</title>
    <link>https://radar.offseq.com/threat/cve-2026-34936-cwe-918-server-side-request-forgery-f70ae3e4</link>
    <guid isPermaLink="true">https://radar.offseq.com/threat/cve-2026-34936-cwe-918-server-side-request-forgery-f70ae3e4</guid>
    <description>CVE-2026-34936: SSRF in PraisonAI</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:24 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-39368: SSRF in WWBN AVideo</title>
    <link>https://radar.offseq.com/threat/cve-2026-39368-cwe-918-server-side-request-forgery-41ed5d8d</link>
    <guid isPermaLink="true">https://radar.offseq.com/threat/cve-2026-39368-cwe-918-server-side-request-forgery-41ed5d8d</guid>
    <description>CVE-2026-39368: SSRF in WWBN AVideo</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:23 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-33182: SSRF in Saloon PHP Library</title>
    <link>https://radar.offseq.com/threat/cve-2026-33182-cwe-918-server-side-request-forgery-18e7372d</link>
    <guid isPermaLink="true">https://radar.offseq.com/threat/cve-2026-33182-cwe-918-server-side-request-forgery-18e7372d</guid>
    <description>CVE-2026-33182: SSRF in Saloon PHP Library</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:22 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-30832: Critical SSRF in Soft Serve</title>
    <link>https://dailycve.com/soft-serve-server-side-request-forgery-ssrf-cve-2026-30832-critical/</link>
    <guid isPermaLink="true">https://dailycve.com/soft-serve-server-side-request-forgery-ssrf-cve-2026-30832-critical/</guid>
    <description>CVE-2026-30832: Critical SSRF in Soft Serve</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:22 +0000</pubDate>
  </item>
  <item>
    <title>Blind SSRF with Burp Collaborator</title>
    <link>https://shivxtar.medium.com/blind-ssrf-with-burp-collaborator-7c2608fcfb73</link>
    <guid isPermaLink="true">https://shivxtar.medium.com/blind-ssrf-with-burp-collaborator-7c2608fcfb73</guid>
    <description>Blind SSRF with Burp Collaborator</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:21 +0000</pubDate>
  </item>
  <item>
    <title>Blind SSRF with Shellshock Exploitation</title>
    <link>https://safe.security/wp-content/uploads/blind-ssrf.pdf</link>
    <guid isPermaLink="true">https://safe.security/wp-content/uploads/blind-ssrf.pdf</guid>
    <description>Blind SSRF with Shellshock Exploitation</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:20 +0000</pubDate>
  </item>
  <item>
    <title>Mastering Blind SSRF Detection With Burp Suite</title>
    <link>https://undercodetesting.com/mastering-blind-ssrf-detection-with-burp-suite-a-step-by-step-guide/</link>
    <guid isPermaLink="true">https://undercodetesting.com/mastering-blind-ssrf-detection-with-burp-suite-a-step-by-step-guide/</guid>
    <description>Mastering Blind SSRF Detection With Burp Suite</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:19 +0000</pubDate>
  </item>
  <item>
    <title>Testing for Blind SSRF with Burp Suite</title>
    <link>https://portswigger.net/burp/documentation/desktop/testing-workflow/ssrf/testing-for-blind-ssrf</link>
    <guid isPermaLink="true">https://portswigger.net/burp/documentation/desktop/testing-workflow/ssrf/testing-for-blind-ssrf</guid>
    <description>Testing for Blind SSRF with Burp Suite</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:19 +0000</pubDate>
  </item>
  <item>
    <title>Blind SSRF Lab: Out-of-Band Detection</title>
    <link>https://portswigger.net/web-security/ssrf/blind/lab-out-of-band-detection</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/ssrf/blind/lab-out-of-band-detection</guid>
    <description>Blind SSRF Lab: Out-of-Band Detection</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:18 +0000</pubDate>
  </item>
  <item>
    <title>Blind SSRF Vulnerabilities - PortSwigger</title>
    <link>https://portswigger.net/web-security/ssrf/blind</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/ssrf/blind</guid>
    <description>Blind SSRF Vulnerabilities - PortSwigger</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:17 +0000</pubDate>
  </item>
  <item>
    <title>Uncovering Blind SSRF Using Burp Collaborator</title>
    <link>https://medium.com/@patilvinay199/uncovering-for-blind-ssrf-using-burp-collaborator-5dd34342d62b</link>
    <guid isPermaLink="true">https://medium.com/@patilvinay199/uncovering-for-blind-ssrf-using-burp-collaborator-5dd34342d62b</guid>
    <description>Uncovering Blind SSRF Using Burp Collaborator</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:16 +0000</pubDate>
  </item>
  <item>
    <title>How SSRF Leads to RCE in a .NET Application</title>
    <link>https://medium.com/@0xUN7H1NK4BLE/how-ssrf-leads-to-rce-in-a-net-application-ee1b13812245</link>
    <guid isPermaLink="true">https://medium.com/@0xUN7H1NK4BLE/how-ssrf-leads-to-rce-in-a-net-application-ee1b13812245</guid>
    <description>How SSRF Leads to RCE in a .NET Application</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:15 +0000</pubDate>
  </item>
  <item>
    <title>From SSRF to RCE: A 7-Step Chain Against PostHog</title>
    <link>https://infosecwriteups.com/from-ssrf-to-rce-a-7-step-chain-against-posthog-d0954b3f26b0</link>
    <guid isPermaLink="true">https://infosecwriteups.com/from-ssrf-to-rce-a-7-step-chain-against-posthog-d0954b3f26b0</guid>
    <description>From SSRF to RCE: A 7-Step Chain Against PostHog</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:15 +0000</pubDate>
  </item>
  <item>
    <title>MCPwnfluence: SSRF to RCE in Atlassian MCP Server (Pluto Security)</title>
    <link>https://pluto.security/blog/mcpwnfluence-cve-2026-27825-critical/</link>
    <guid isPermaLink="true">https://pluto.security/blog/mcpwnfluence-cve-2026-27825-critical/</guid>
    <description>MCPwnfluence: SSRF to RCE in Atlassian MCP Server (Pluto Security)</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:14 +0000</pubDate>
  </item>
  <item>
    <title>Blind SSRF to RCE Vulnerability Exploitation</title>
    <link>https://www.resecurity.com/blog/article/blind-ssrf-to-rce-vulnerability-exploitation</link>
    <guid isPermaLink="true">https://www.resecurity.com/blog/article/blind-ssrf-to-rce-vulnerability-exploitation</guid>
    <description>Blind SSRF to RCE Vulnerability Exploitation</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:13 +0000</pubDate>
  </item>
  <item>
    <title>SSRF: From Ping to RCE</title>
    <link>https://medium.com/@Aacle/server-side-request-forgery-ssrf-from-ping-to-rce-6ac95bf4e489</link>
    <guid isPermaLink="true">https://medium.com/@Aacle/server-side-request-forgery-ssrf-from-ping-to-rce-6ac95bf4e489</guid>
    <description>SSRF: From Ping to RCE</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:12 +0000</pubDate>
  </item>
  <item>
    <title>MCPwnfluence: Critical SSRF to RCE in mcp-atlassian (Pluto Security)</title>
    <link>https://blog.pluto.security/p/mcpwnfluence-cve-2026-27825-critical</link>
    <guid isPermaLink="true">https://blog.pluto.security/p/mcpwnfluence-cve-2026-27825-critical</guid>
    <description>MCPwnfluence: Critical SSRF to RCE in mcp-atlassian (Pluto Security)</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:12 +0000</pubDate>
  </item>
  <item>
    <title>MindsDB: Bypass SSRF Protection with DNS Rebinding</title>
    <link>https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4jcv-vp96-94xr</link>
    <guid isPermaLink="true">https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4jcv-vp96-94xr</guid>
    <description>MindsDB: Bypass SSRF Protection with DNS Rebinding</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:11 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-27127: Weaponizing DNS Rebinding to Bypass SSRF Filters in Craft CMS</title>
    <link>https://cvereports.com/reports/CVE-2026-27127</link>
    <guid isPermaLink="true">https://cvereports.com/reports/CVE-2026-27127</guid>
    <description>CVE-2026-27127: Weaponizing DNS Rebinding to Bypass SSRF Filters in Craft CMS</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:10 +0000</pubDate>
  </item>
  <item>
    <title>Bypassing SSRF Protection in nossrf: When Safeguards Become Loopholes</title>
    <link>https://www.nodejs-security.com/blog/bypassing-ssrf-protection-nossrf</link>
    <guid isPermaLink="true">https://www.nodejs-security.com/blog/bypassing-ssrf-protection-nossrf</guid>
    <description>Bypassing SSRF Protection in nossrf: When Safeguards Become Loopholes</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:10 +0000</pubDate>
  </item>
  <item>
    <title>Using DNS To Bypass SSRF Protections</title>
    <link>https://blog.cyberadvisors.com/technical-blog/blog/using-dns-to-bypass-ssrf-protections</link>
    <guid isPermaLink="true">https://blog.cyberadvisors.com/technical-blog/blog/using-dns-to-bypass-ssrf-protections</guid>
    <description>Using DNS To Bypass SSRF Protections</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:09 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-27127: Craft CMS Cloud Metadata SSRF via DNS Rebinding</title>
    <link>https://advisories.gitlab.com/pkg/composer/craftcms/cms/CVE-2026-27127/</link>
    <guid isPermaLink="true">https://advisories.gitlab.com/pkg/composer/craftcms/cms/CVE-2026-27127/</guid>
    <description>CVE-2026-27127: Craft CMS Cloud Metadata SSRF via DNS Rebinding</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:08 +0000</pubDate>
  </item>
  <item>
    <title>HackerOne: SSRF Mitigation Bypass Using DNS Rebind Attack</title>
    <link>https://hackerone.com/reports/1369312</link>
    <guid isPermaLink="true">https://hackerone.com/reports/1369312</guid>
    <description>HackerOne: SSRF Mitigation Bypass Using DNS Rebind Attack</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:07 +0000</pubDate>
  </item>
  <item>
    <title>SSRF with DNS Rebinding - Clear Gate</title>
    <link>https://www.clear-gate.com/blog/ssrf-with-dns-rebinding-2/</link>
    <guid isPermaLink="true">https://www.clear-gate.com/blog/ssrf-with-dns-rebinding-2/</guid>
    <description>SSRF with DNS Rebinding - Clear Gate</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:07 +0000</pubDate>
  </item>
  <item>
    <title>Bypass SSRF with DNS Rebinding</title>
    <link>https://h3des.medium.com/bypass-ssrf-with-dns-rebinding-6811093fceb0</link>
    <guid isPermaLink="true">https://h3des.medium.com/bypass-ssrf-with-dns-rebinding-6811093fceb0</guid>
    <description>Bypass SSRF with DNS Rebinding</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:06 +0000</pubDate>
  </item>
  <item>
    <title>Meta Bug Bounty: SSRF Payout Guidelines</title>
    <link>https://bugbounty.meta.com/payout-guidelines/ssrf/</link>
    <guid isPermaLink="true">https://bugbounty.meta.com/payout-guidelines/ssrf/</guid>
    <description>Meta Bug Bounty: SSRF Payout Guidelines</description>
    <category>SSRF</category>
    <pubDate>Fri, 10 Apr 2026 01:59:05 +0000</pubDate>
  </item>
</channel>
</rss>