VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,681)

page 112 of 185
  • CVE-2026-48782MedJun 17, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous…

  • CVE-2026-42194MedMay 7, 2026
    risk 0.37cvss 6.8epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding TOCTOU window that allows…

  • CVE-2026-42038MedApr 24, 2026
    risk 0.37cvss 6.8epss 0.00

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it.…

  • CVE-2026-33486MedMar 26, 2026
    risk 0.37cvss 6.8epss 0.00

    Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulnerability in roadiz/documents prior to versions 2.7.9, 2.6.28, 2.5.44, and 2.3.42 allows an authenticated attacker to read any file on the server's local file…

  • CVE-2026-32279MedMar 23, 2026
    risk 0.37cvss 6.8epss 0.00

    Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin.…

  • CVE-2026-32812MedMar 20, 2026
    risk 0.37cvss 6.8epss 0.00

    Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSRF and local file reads. The SSO Metadata fetch endpoint at modules/sso/fetch_metadata.php accepts an arbitrary URL via…

  • CVE-2026-28423MedFeb 27, 2026
    risk 0.37cvss 6.8epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP…

  • CVE-2025-68437MedJan 5, 2026
    risk 0.37cvss 6.8epss 0.00

    Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save__Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the `_file`…

  • CVE-2025-12136MedOct 24, 2025
    risk 0.37cvss 6.8epss 0.00

    The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.2.4. This is due to insufficient validation on the user-supplied URL in the '/scanner/scan-without-login' REST API…

  • CVE-2025-7622MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.00

    During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.

  • CVE-2024-37895MedJun 17, 2024
    risk 0.37cvss 5.7epss 0.01

    Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side…

  • CVE-2023-50714MedDec 22, 2023
    risk 0.37cvss 6.8epss 0.00

    yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCodeVerifier` should be removed after usage…

  • CVE-2021-43959MedJul 26, 2022
    risk 0.37cvss 5.7epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running…

  • CVE-2022-28117MedApr 28, 2022
    risk 0.37cvss 4.9epss 0.23

    A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

  • CVE-2026-100900MedSep 28, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side…

  • CVE-2026-12037MedSep 25, 2026
    risk 0.36cvss 5.5epss 0.00

    The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to…

  • CVE-2026-53708MedSep 14, 2026
    risk 0.36cvss 6.6epss 0.00

    ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in…

  • CVE-2026-84772MedSep 2, 2026
    risk 0.36cvss 5.5epss 0.00

    Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.

  • CVE-2026-16910MedJul 24, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses…

  • CVE-2026-14645MedJul 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations…