
SSRF-Testing
SSRF (Server Side Request Forgery) testing resources

SSRF (Server Side Request Forgery) testing resources

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.

A collection of awesome penetration testing resources, tools and other shiny things

Structured study notes covering web hacking fundamentals, common vulnerabilities, penetration testing techniques, and defensive security, with…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

Nuclei Templates Collection

Collection of Proof of Concepts and Potential Targets for #ShellShocker

Proof of concept code for Datadog Security Labs referenced exploits.

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Awesome information for WebSockets security research

A collection oneliner scripts for bug bounty

Random Wordpres Exploits May or May Not Work.

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page