Protocol Smuggling in SSRF: gopher, dict and file Schemes
When an SSRF fetcher accepts non-HTTP schemes, the attack stops being about reaching internal HTTP and starts being about speaking arbitrary protocols. gopher:// crafts raw TCP bytes to reach Redis or SMTP, dict:// probes services, and file:// reads local files. Here is how the smuggling works and how a strict scheme allowlist stops it.