@洪 民憙 (Hong Minhee) :nonbinary:>So I would not phrase it as “documentation or multicast addresses are always practical SSRF targets.”
But could they be, even in theory? I found that 100.64.0.0/10 is indeed used for private networks, but it seems that allowing requests to documentation or multicast addresses has no security impact.