SSRF: Control specification
Specifies server-side request forgery controls using allowlisted schemes and hosts, resolve-then-recheck DNS, blocking of link-local and cloud metadata destinations, and a ban on using caller URLs as an open proxy.
Referencev0.1.0NOASSERTION
Published Sep 12, 2026