SSRF turns a server into an unwilling proxy for the attacker. The classic target is internal metadata endpoints that were never meant to be reachable from outside.
The usual entry point
Any feature that fetches a URL on the user’s behalf — link previews, webhook testers, image proxies — is worth testing with an internal IP or a redirect chain that lands on one.