SSRF forces a server to make HTTP requests to internal resources or external systems on the attacker's behalf.
Enables internal network scanning, cloud metadata access (AWS IMDSv1: 169.254.169.254), and firewall bypass.
Mitigation
URL allowlist, block internal IP ranges, enforce IMDSv2.