We present a large-scale automated study of Server-Side Request Forgery (SSRF) vulnerabilities across 23 major bug bounty programs using a structured pipeline combining reconnaissance automation, multi-endpoint probing, response classification, and LLM-enriched analysis via the Saif cybersecurity AI system. Over a two-week period, we probed 23 programs using three standardized SSRF test endpoints — /proxy?url=, /fetch?url=, and /redirect?url= — and classified responses on a five-tier severity sc
1@techreport{hayulalab2026ssrfdiscoveryatscale,
2 title={SSRF Discovery at Scale: A Multi-Program Study Using Automated Reconnaissance and — Hayula Research},
3 author={Hayula AI Lab},
4 year={2026},
5 url={https://huggingface.co/hayulalab/ssrf-discovery-at-scale-paper}
6}