API7:2023 Server-Side Request Forgery
User-controlled URLs are fetched by the server. The attacker steers requests at internal hosts (cloud metadata services, RFC1918 ranges), bypassing perimeter firewalls.
What Vulkro detects
Vulkro tracks taint from request body / query / path into HTTP client calls (requests.get, axios, fetch, http.Client.Get, etc.) without intervening URL validation or allowlist check.