Server-side request forgery in webhook validator
The outbound webhook validator follows attacker-controlled redirects without re-checking the destination, letting a crafted callback URL reach the internal metadata service. Confirmed: retrieved an IAM credential from the staging instance role. Reproduction, request captures, and a scoped PoC are attached in the platform.