WAF accepted outbound requests to arbitrary URLs including 169.254.169.254. IMDSv1 was in use (GET-only metadata access). IAM role had overly broad S3 permissions across all company buckets.
API accepted arbitrary URLs in YAML include directives with no authentication and no URL validation. Cloud-hosted GitLab instances had their metadata endpoints exposed.
Hostname check passed, but resolved to internal IP. Admin panel trusted all internal callers. Raw response returned in webhook test result.
No protocol restriction on the URL parameter. URL-fetching library supported file:// by default. Raw response returned to caller.