Webhook-url-http-3a-2f-2f169.254.169.254-2fmetadata-2fidentity-2foauth2-2ftoken Jun 2026
used by major cloud providers for Instance Metadata Services (IMDS). /metadata/identity/oauth2/token
http://169.254.169.254/metadata/identity/oauth2/token used by major cloud providers for Instance Metadata
GET /metadata/identity/oauth2/token?api-version=2018-02-01&resource= https://management.azure.com/ HTTP/1.1 Host: 169.254.169.254 Metadata: true used by major cloud providers for Instance Metadata
If your system accepts webhook URLs from users, you are vulnerable. Here is the fix: used by major cloud providers for Instance Metadata