Page fetching and image proxies: SSRF beyond the public edge

A valid-looking request can trigger unsafe backend fetches. Review outbound access for proxies and converters.

Contents of this article

Inbound and outbound paths are different

Image proxies, page previews and converters fetch content on a user’s behalf. OWASP’s SSRF guidance addresses destination and network restrictions. Edge inspection cannot replace backend authorization and outbound controls.

Identify legitimate destinations

For fixed partners, define explicit allowed destinations. Arbitrary public fetching needs additional checks around resolved addresses, redirects and outbound routing. Do not pass user URLs directly to a process with broad internal access.

Bound the processing cost

Set limits on response size, connection time, total processing time and concurrency, and isolate heavy conversion jobs. This bounds resource impact and allows failures from one destination to be handled separately.

Test rejection paths

Use controlled targets to test denied destinations, redirects and oversized responses. Avoid logging tokens or personal data embedded in URLs, and assign maintenance of the checks to the application owner.

References

OWASP SSRF Prevention Cheat Sheet

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support