Skip to main content

Exploiting XXE to perform SSRF attacks

$ tldr PortSwigger · XXE (XML External Entity)

Solve the lab

Resources by skill

XML External Entity · Server-Side Request Forgery

Comments & tips

Solved this lab a different way? Share it here — comments live in GitHub Discussions.
Last updated: 2026-05-08