Security researcher Evan Ikeda has published details and a PoC for an SSF vulnerability in the Havoc C2 server, a toolkit commonly used by threat actors to host malware command and control servers
https://blog.chebuya.com/posts/server-side-request-forgery-on-havoc-c2/