VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,681)

page 115 of 185
  • CVE-2026-66608MedSep 17, 2026
    risk 0.35cvss 6.4epss 0.00

    Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

  • CVE-2026-92795MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable…

  • CVE-2026-92789MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redirect to internal services,…

  • CVE-2026-92775MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate…

  • CVE-2026-54688MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.01

    mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllowed() in src/url-reader.ts runs only when…

  • CVE-2026-91750MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation by supplying a public URL that redirects…

  • CVE-2026-12766MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2026-73497MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once at middleware time, but the…

  • CVE-2026-15887MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

  • CVE-2026-57115MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loopback, private, link-local, or metadata…

  • CVE-2026-54054MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Transmute is a free, open-source, self-hosted file conversion and compression tool. Prior to version 1.3.0, Transmute's URL import endpoint, `POST /api/files/url`, is vulnerable to Server-Side Request Forgery (SSRF). The HTTP downloader used by this endpoint fetches…

  • CVE-2026-86082MedSep 8, 2026
    risk 0.35cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an…

  • CVE-2026-86100MedSep 5, 2026
    risk 0.35cvss 6.4epss 0.00

    Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side…

  • CVE-2026-85305MedSep 3, 2026
    risk 0.35cvss 5.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.

  • CVE-2026-85172MedSep 3, 2026
    risk 0.35cvss 6.4epss 0.00

    n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client uses the url property when both…

  • CVE-2026-84377MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.01

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured…

  • CVE-2025-15613MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify an external URL in a policy's apiCall/service configuration; although Service Call is…

  • CVE-2026-82852MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.

  • CVE-2026-82081MedAug 28, 2026
    risk 0.35cvss 6.4epss 0.00

    wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

  • CVE-2026-78269MedAug 24, 2026
    risk 0.35cvss 6.4epss 0.00

    Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.