VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,681)

page 116 of 185
  • CVE-2026-72846MedAug 20, 2026
    risk 0.35cvss 6.4epss 0.00

    Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call…

  • CVE-2026-63044MedAug 20, 2026
    risk 0.35cvss 5.4epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong:…

  • CVE-2026-76347MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send…

  • CVE-2026-73560MedAug 17, 2026
    risk 0.35cvss 6.5epss 0.00

    vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, requests.get, and Image.open…

  • CVE-2026-75053MedAug 17, 2026
    risk 0.35cvss 5.4epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

  • CVE-2026-62902MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.01

    Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-16027MedAug 7, 2026
    risk 0.35cvss 5.4epss 0.00

    Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.

  • CVE-2026-70367MedAug 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or…

  • CVE-2026-67530MedJul 30, 2026
    risk 0.35cvss 6.4epss 0.00

    WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its validation in src/lib/automations/validate.ts allowed an authenticated user with automation privileges to submit an arbitrary…

  • CVE-2026-64649MedJul 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host…

  • CVE-2026-63743MedJul 20, 2026
    risk 0.35cvss 6.4epss 0.00

    SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:port combination, and the…

  • CVE-2026-56678MedJul 15, 2026
    risk 0.35cvss 6.4epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region value, allowing an authenticated attacker to supply a crafted region such as kiro-canary.local:8443# and…

  • CVE-2026-15746MedJul 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request…

  • CVE-2026-54562MedJul 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or…

  • CVE-2026-57211MedJul 10, 2026
    risk 0.35cvss 6.5epss 0.01

    RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management…

  • CVE-2026-12123MedJul 10, 2026
    risk 0.35cvss 6.4epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to…

  • CVE-2026-45796MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint…

  • CVE-2026-58418MedJul 3, 2026
    risk 0.35cvss 6.5epss 0.00

    SSRF via HTTP Redirect in Repository Migration

  • CVE-2026-56227MedJun 20, 2026
    risk 0.35cvss 5.4epss 0.00

    Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound…

  • CVE-2026-49345MedJun 19, 2026
    risk 0.35cvss —epss 0.01

    Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery (SSRF) vulnerability exists in Mercator's CVE configuration panel (`/admin/config/parameters`). The `testProvider()` method in…