Cisco CUCM CVE-2026-20230 SSRF - Internal Host References in HTTP Requests

Detects HTTP requests where the URI or request body contains indicators of internal network references (e.g., localhost, 127.0.0.1, or RFC 1918 private IP address ranges). This pattern is consistent with Server-Side Request Forgery (SSRF) attempts, where an attacker tries to force a vulnerable web application to perform unauthorized requests to internal resources.