VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,681)

page 111 of 185
  • CVE-2020-16248MedAug 9, 2020
    risk 0.38cvss 5.8epss 0.03

    Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

  • CVE-2020-6282MedJul 14, 2020
    risk 0.38cvss 5.8epss 0.01

    SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web…

  • CVE-2019-6516MedMay 14, 2019
    risk 0.38cvss 5.8epss 0.02

    An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.

  • CVE-2019-11767MedMay 5, 2019
    risk 0.38cvss 5.8epss 0.01

    Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.

  • CVE-2018-15516MedJan 31, 2019
    risk 0.38cvss 5.8epss 0.02

    The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.

  • CVE-2016-4046MedDec 15, 2016
    risk 0.38cvss 5.8epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending…

  • CVE-2026-100858MedSep 27, 2026
    risk 0.37cvss 6.8epss 0.00

    heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the…

  • CVE-2026-76900MedSep 18, 2026
    risk 0.37cvss 6.8epss 0.01

    CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and passes it through…

  • CVE-2026-55421MedSep 2, 2026
    risk 0.37cvss 6.8epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allow_redirects=True)". The fetched bytes are then returned inside…

  • CVE-2026-82866MedAug 31, 2026
    risk 0.37cvss 6.8epss 0.00

    @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to…

  • CVE-2026-82263MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.00

    Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET…

  • CVE-2026-82262MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.00

    Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs…

  • CVE-2026-55535MedAug 25, 2026
    risk 0.37cvss 6.8epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or…

  • CVE-2026-46380MedAug 14, 2026
    risk 0.37cvss 6.7epss 0.00

    compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request…

  • CVE-2026-70620MedAug 4, 2026
    risk 0.37cvss 6.8epss 0.00

    Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range,…

  • CVE-2026-67311MedAug 1, 2026
    risk 0.37cvss 6.8epss 0.00

    Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns…

  • CVE-2026-54249MedJul 29, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in…

  • CVE-2026-46678MedJul 29, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be…

  • CVE-2026-46404MedJul 16, 2026
    risk 0.37cvss 6.8epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved IPs. This issue is fixed in version 3.0.23.

  • CVE-2026-58404MedJul 6, 2026
    risk 0.37cvss 6.8epss 0.00

    Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alternate IPv4 encodings of the same…