VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 134 of 184
  • CVE-2022-45027MedJan 1, 2023
    risk 0.34cvss 5.3epss 0.01

    perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.

  • CVE-2022-3189MedDec 21, 2022
    risk 0.34cvss 5.3epss 0.01

    Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another…

  • CVE-2022-39055MedOct 18, 2022
    risk 0.34cvss 5.3epss 0.00

    RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.

  • CVE-2017-20106MedJun 28, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to…

  • CVE-2022-21697MedJan 25, 2022
    risk 0.34cvss 6.3epss 0.01

    Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (SSRF). Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled is…

  • CVE-2020-11980MedJun 12, 2020
    risk 0.34cvss 6.3epss 0.02

    In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on an MBean. However there is a vulnerability there for someone who is not an admin, but has a "viewer" role. In the…

  • CVE-2026-91967MedSep 15, 2026
    risk 0.33cvss 5.0epss 0.00

    AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store attacker-chosen URLs as video…

  • CVE-2026-91199MedSep 14, 2026
    risk 0.33cvss 5.0epss 0.00

    Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback,…

  • CVE-2026-55073MedSep 14, 2026
    risk 0.33cvss 6.2epss 0.00

    WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or stylesheets options. In…

  • CVE-2026-79723MedSep 10, 2026
    risk 0.33cvss 5.0epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

  • CVE-2026-4361MedSep 5, 2026
    risk 0.33cvss 5.0epss 0.00

    The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image…

  • CVE-2026-17631MedSep 4, 2026
    risk 0.33cvss 5.0epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

  • CVE-2026-19301MedSep 4, 2026
    risk 0.33cvss 5.0epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.

  • CVE-2026-78500MedAug 28, 2026
    risk 0.33cvss —epss 0.00

    A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

  • CVE-2026-78499MedAug 28, 2026
    risk 0.33cvss —epss 0.00

    A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

  • CVE-2026-78498MedAug 28, 2026
    risk 0.33cvss —epss 0.00

    A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

  • CVE-2026-64968MedAug 20, 2026
    risk 0.33cvss —epss 0.00

    ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers. …

  • CVE-2026-20314MedAug 19, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This…

  • CVE-2026-19075MedAug 10, 2026
    risk 0.33cvss 5.0epss 0.00

    All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back…

  • CVE-2026-18736MedAug 3, 2026
    risk 0.33cvss 5.0epss 0.00

    Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs…