Page fetching and image proxies: SSRF beyond the public edge
A valid-looking request can trigger unsafe backend fetches. Review outbound access for proxies and converters.
Contents of this article
Inbound and outbound paths are different
Image proxies, page previews and converters fetch content on a user’s behalf. OWASP’s SSRF guidance addresses destination and network restrictions. Edge inspection cannot replace backend authorization and outbound controls.
Identify legitimate destinations
For fixed partners, define explicit allowed destinations. Arbitrary public fetching needs additional checks around resolved addresses, redirects and outbound routing. Do not pass user URLs directly to a process with broad internal access.
Bound the processing cost
Set limits on response size, connection time, total processing time and concurrency, and isolate heavy conversion jobs. This bounds resource impact and allows failures from one destination to be handled separately.
Test rejection paths
Use controlled targets to test denied destinations, redirects and oversized responses. Avoid logging tokens or personal data embedded in URLs, and assign maintenance of the checks to the application owner.
References
OWASP SSRF Prevention Cheat Sheet
