Server-side request forgery

Server-side request forgery

Description

Using user input as the URL in external-request APIs such as curl_init, curl_setopt, file_get_contents, or fopen can allow server-side request forgery (SSRF).

Potential impact

Attackers may probe internal networks, access cloud metadata, or bypass access restrictions on internal services.

Remediation

Select URLs from a fixed allow-list and block private IP ranges and dangerous protocols.

Examples

Before

php
<?php
$url = $_GET['url'];
$body = file_get_contents($url);

After

php
<?php
$allowed = ['status' => 'https://status.example.com/health'];
$target = $_GET['target'] ?? '';
if (!isset($allowed[$target])) {
    http_response_code(400);
    exit;
}

$context = stream_context_create(['http' => ['follow_location' => 0]]);
$body = file_get_contents($allowed[$target], false, $context);

Explanation:

  • Before: The user controls the destination URL sent to the request API.
  • After: Input selects a key in the server-managed allow-list, rather than supplying a URL. Unknown destinations are rejected and redirects are disabled. Restrict DNS resolution results and outbound network access to prevent connections to internal addresses.

References