Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications
Enze Wang, Jianjun Chen, Wei Xie, Chuhan Wang, Yifei Gao, Zhenhua Wang, Haixin Duan, Yang Liu, Baosheng Wang
Abstract
Server-Side Request Forgery (SSRF) vulnerability poses significant security risks to web applications, enabling adversaries to exploit web applications as stepping stones for unauthorized access of internal-only services or even performing arbitrary commands. Despite its recent emergence as a distinct category in the 2021 OWASP Top 10 web security risks and its increasing prevalence in modern web applications, there remains a lack of effective approaches to detect SSRF vulnerabilities systematically.We present a novel methodology, SSRFuzz, to effectively identify SSRF vulnerability in PHP web applications. Our methodology consists of three phases. In the initial phase, we designed an SSRF oracle to examine functions in PHP manuals and identify sinks that provide server-side request capabilities. This process yielded a total of 86 sensitive PHP sinks out of 2101 PHP functions. The second stage involves dynamic taint inference and the utilization of the identified sinks to examine the source code of target web applications, pinpointing all feasible input points that could trigger these sinks. The final phase employs fuzzing techniques. We generate testing HTTP requests with SSRF payloads, send them to the previously identified input points within the target web applications, and detect if an SSRF vulnerability is triggered. We implemented a prototype of SSRFuzz and evaluated it on 27 real-world applications, including Joomla and WordPress. In total, we discovered 28 SSRF vulnerabilities, 25 of which were previously unreported. We reported all the vulnerabilities to the affected vendors, and 16 new CVE IDs were assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a367d4b6-321a-4aa5-a5bf-fb7dc9cc1c32Cited by top-tier papers11
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler et al.NDSS 2026 · 4 citations
- Detecting Broken Object-Level Authorization Vulnerabilities in Database-Backed ApplicationsYongheng Huang, Chenghang Shi, Jie Lu, Haofeng Li et al.CCS 2024 · 4 citations
- Contextualizing Sink Knowledge for Java Vulnerability DiscoveryFabian Fleischer, Cen Zhang, Joonun Jang, Jeongin Cho et al.S&P 2026 · 2 citations
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge et al.NDSS 2026 · 1 citation
Builds on10
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement LearningSoyoung Lee, Seongil Wi, Sooel SonWWW 2022 · 34 citations
- LChecker: Detecting Loose Comparison Bugs in PHPPenghui Li, Wei MengWWW 2021 · 22 citations
- Deceptive Previews: A Study of the Link Preview Trustworthiness in Social PlatformsGiada Stivala, Giancarlo PellegrinoNDSS 2020
Related papers
- SSRF vs. Developers: A Study of SSRF-Defenses in PHP ApplicationsMalte Wessels, Simon Koch, Giancarlo Pellegrino, Martin JohnsUSENIX Security 2024 · 8 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Argus: All your (PHP) Injection-sinks are belong to usRasoul Jahanshahi, Manuel EgeleUSENIX Security 2024 · 1 citation
- XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent FuzzingYoukun Shi, Yuan Zhang, Tianhao Bai, Feng Xue et al.USENIX Security 2025
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui et al.USENIX Security 2025
