Glossary · Network and discovery
Server-side request forgery (SSRF)
An attack that makes a server send requests to destinations the attacker picks, such as internal services or cloud metadata, via URLs the server fetches.
Server-side request forgery (SSRF) is an attack in which someone makes a server send requests to a destination the attacker chooses, usually by supplying a URL that the server then fetches.
Why it works. A server often sits inside a network perimeter and can reach things the attacker cannot: internal admin panels, databases, services on localhost, and cloud metadata endpoints such as 169.254.169.254, which can expose credentials. The server becomes the attacker’s proxy past the firewall. The MCP security guidance lists common variants, including redirect chains to internal addresses and DNS rebinding, where a hostname resolves to a safe address when checked and an internal one when used.
Where agents meet it. Agent protocols pass many URLs from one party to another for fetching:
- A2A push-notification webhook URLs. The specification says agents should validate them, rejecting private IP ranges, localhost and link-local addresses, and use allowlists where appropriate.
- File parts that reference a URL. The A2A media type registration requires file references to be validated to prevent SSRF.
- Agent Card URLs and JWK Set URLs in
jkuheaders, which validators, registries and clients fetch. - OAuth metadata URLs that an MCP server hands a client, which the MCP guidance identifies as an SSRF vector.
Defences. The OWASP SSRF Prevention Cheat Sheet recommends an allowlist of destinations wherever the set is known. Where any external host must be allowed, as with webhooks, it recommends checking that every IP address the name resolves to is public, allowing only HTTP or HTTPS, disabling automatic redirects, and adding network-level controls. As a working example, Emissar’s Agent Card validator fetches domains that users type in, so it accepts only HTTPS on port 443, refuses IP addresses, localhost, single-label names and .local or .internal hosts, follows at most three redirects and re-checks each one, and stops at 256 KB or 5 seconds.
Standing in OWASP’s lists. SSRF had its own category, A10, in the OWASP Top 10:2021. The 2025 edition maps it, as CWE-918, under A01 Broken Access Control.
Neighbouring terms. SSRF is a network form of the confused deputy problem: the server’s reach is used for a caller who lacks it. CORS governs the reverse direction, what browsers let pages read.
Sources
- OWASP Cheat Sheet Series: Server-Side Request Forgery Prevention (accessed )
- OWASP Top 10:2021, A10: Server-Side Request Forgery (SSRF) (accessed )
- OWASP Top 10:2025, A01: Broken Access Control (accessed )
- A2A Protocol Specification, section 13.2: Push Notification Security (accessed )
- A2A Protocol Specification, section 14.1: Media Type Registration (security considerations) (accessed )
- MCP documentation: Security Best Practices (accessed )