FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

server-side-request-forgery · GitHub Topics · GitHub

#

server-side-request-forgery

Here are 29 public repositories matching this topic...

Automatic SSRF fuzzer and exploitation tool

  • Updated Aug 10, 2026
  • Python

SSRF (Server Side Request Forgery) testing resources

  • Updated Oct 12, 2024
  • Python

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

  • Updated Aug 21, 2023
  • PHP

A ruby gem for defending against Server Side Request Forgery (SSRF) attacks

  • Updated Jul 6, 2026
  • Ruby

A comprehensive browser extension designed for authorized security testing and penetration testing activities. CyberInject provides quick access to common security payloads across multiple vulnerability categories.

  • Updated Jun 21, 2026
  • HTML

Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1)

  • Updated Aug 9, 2023
  • Shell

An ongoing & curated collection of awesome web vulnerability - Server-side request forgery software practices and remediation, libraries and frameworks, best guidelines and technical resources about SSRF

  • Updated Feb 22, 2022
  • Python

Module to prevent SSRF when sending requests in NodeJS. Blocks request to local and private IP addresses

  • Updated Aug 4, 2026
  • JavaScript

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

  • Updated Oct 22, 2024
  • Java

CVE-2021-40438 Apache <= 2.4.48 SSRF exploit

  • Updated Dec 12, 2023
  • Python

Automated blind SSRF scanner with native PingBack.sh OAST correlation, persistent callbacks and exact injection tracking.

  • Updated Aug 1, 2026
  • Go

CloudSSRFer tests SSRF on Amazon AWS cloud to extract sensitive information.

  • Updated Mar 20, 2026
  • Python

Server-Side Request Forgery (SSRF) protection plugin for HTTPlug

  • Updated Aug 24, 2026
  • PHP

SSRF, Server-Side Request Forgery: Exploiting a vulnerable avatar fetching feature using directory traversal to force the server to access an internal /private endpoint and retrieve a base64-encoded flag.

  • Updated Jul 13, 2026

Drop-in SSRF protection for httpx

  • Updated Aug 16, 2025
  • Python

Lightweight SSRF (Server-Side Request Forgery) protection for HttpClient in .NET microservices.

  • Updated Feb 17, 2026
  • C#

Header-based SSRF (scanner-for-debugging) fuzzing utility inspired by a HackerOne Blind SSRF report. Automates injection of Forwarded-type headers, detects time-delay behavior and 429 responses, supports authenticated flows, logs results, and optionally integrates Telegram notifications for controlled security testing.

  • Updated Feb 21, 2026
  • Python

This is a difficult web exploitation task. To solve it, I must exploit a Server-Side Request Forgery (SSRF) vulnerability in Git webhooks and use template injection. This allowed me to gain admin privileges via localhost, create a custom Git packfile to add myself as a collaborator to the hidden repository, and then clone it to read the flag.

  • Updated Oct 19, 2025

Improve this page

Add a description, image, and links to the server-side-request-forgery topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the server-side-request-forgery topic, visit your repo's landing page and select "manage topics."

Learn more


Back | FazBrowse Home | New Git URL