Description
Using user input as the URL in external-request APIs such as curl_init, curl_setopt, file_get_contents, or fopen can allow server-side request forgery (SSRF).
Potential impact
Attackers may probe internal networks, access cloud metadata, or bypass access restrictions on internal services.
Remediation
Select URLs from a fixed allow-list and block private IP ranges and dangerous protocols.
Examples
Before
php
<?php
$url = $_GET['url'];
$body = file_get_contents($url);
After
php
<?php
$allowed = ['status' => 'https://status.example.com/health'];
$target = $_GET['target'] ?? '';
if (!isset($allowed[$target])) {
http_response_code(400);
exit;
}
$context = stream_context_create(['http' => ['follow_location' => 0]]);
$body = file_get_contents($allowed[$target], false, $context);
Explanation:
- Before: The user controls the destination URL sent to the request API.
- After: Input selects a key in the server-managed allow-list, rather than supplying a URL. Unknown destinations are rejected and redirects are disabled. Restrict DNS resolution results and outbound network access to prevent connections to internal addresses.