Web Hack List

Collected research

SSRF Cross Protocol Redirect Bypass

The Node.js request library deletes the custom HTTP agent whenever a redirect switches protocol, which silently discards the anti-SSRF filter attached to that agent. An attacker-controlled open redirect from HTTPS to HTTP therefore defeats ssrf-req-filter and reaches internal services (CVE-2023-28155); axios is exposed the same way when only one of its two agents is overridden.

Record

Researcher
Szymon Drosdzol
Published by
blog.doyensec.com
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Szymon Drosdzol, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .