Safeguard
Tag

ssrf

Safeguard articles tagged "ssrf" — guides, analysis, and best practices for software supply chain and application security.

46 articles

Application Security

A Link Is Fetched Before Anyone Clicks It

Paste a URL into a chat message and a server fetches it automatically to build a preview card, before anyone reads the message or clicks anything. That fetch consumes a single-use link or a time-limited token just as effectively as the intended recipient would have.

Sep 18, 20267 min read
Application Security

Your PDF Generator Is a Browser You Handed to Your Users

Behind the invoice feature is a headless browser running inside your network, rendering markup a user influenced. Everything a browser does it will do: fetch URLs, load images, follow redirects. The only question is where it can reach.

Sep 18, 20265 min read
Vulnerability Analysis

Capital One (2019): An SSRF Misconfiguration Breach in the Cloud

A factual retrospective on the 2019 Capital One breach, in which a server-side request forgery flaw against a misconfigured WAF allowed access to AWS metadata credentials and over 100 million customer records.

Sep 17, 20262 min read
Vulnerability Analysis

When the Security Console Becomes the Distribution Path: Apex One and Workspace ONE UEM

A directory traversal bug in Trend Micro Apex One and a four-year-old SSRF flaw in Omnissa Workspace ONE UEM both use management-plane trust against the fleets these tools are meant to protect.

Sep 16, 20265 min read
Vulnerability Analysis

Two More GitLab SSRF Bugs, Reached Through Webhooks and the CI Lint API

An additional pair of GitLab server-side request forgery vulnerabilities, distinct from the CVE covered earlier in this series, both confirmed exploited within weeks of each other.

Sep 16, 20264 min read
Vulnerability Analysis

Four SonicWall SMA1000 CVEs, Two Confirmed for Ransomware, Ten Weeks Apart

SonicWall's SMA1000 VPN appliance had four vulnerabilities confirmed exploited in 2026, two of them flagged by CISA for confirmed ransomware use. The same two bug classes, in the same two interfaces, twice.

Sep 16, 20265 min read
Vulnerability Analysis

Langflow, MLflow, Ray, LiteLLM and Kestra: AI Orchestration Platforms Enter CISA's KEV Catalogue

Five AI and ML orchestration platforms had vulnerabilities confirmed as exploited in the wild between July and September 2026 — Langflow twice, then MLflow, Ray, and Kestra. Five different root causes, one shared category.

Sep 16, 20265 min read
Application Security

A Scanner's Scope Guard Belongs in Code, Not in a Config File

The difference between a security test and an unauthorised attack is permission on the target. If that boundary is a setting, then a typo, a redirect or a merged config is all it takes to cross it.

Aug 16, 20264 min read
Vulnerability Analysis

Python urllib.parse NFKC normalization blocklist bypass (CVE-2023-24329)

CVE-2023-24329 let attackers bypass URL blocklists via leading blank characters in Python's urllib.parse, enabling SSRF and filter evasion.

Aug 9, 20267 min read
Vulnerability Analysis

Server-Side Request Forgery (SSRF): how it works and how to prevent it

SSRF turns a server into an attacker's proxy into your internal network. Here's how it works, what Capital One's breach taught the industry, and how to stop it.

Aug 3, 20266 min read
Vulnerability Analysis

SSRF via webhooks explained

Webhook SSRF turns a trusted callback feature into an internal network foothold. Here is how the attack works, real incidents, and how to actually fix it.

Jul 29, 20267 min read
Application Security

URL parser confusion: how inconsistent parsing enables SSRF and auth bypass

Sixteen URL-parsing libraries tested, five inconsistency classes found, eight CVEs assigned — one wrong backslash can turn a validated URL into an SSRF.

Jul 16, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.