CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,680)
page 137 of 184| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3172 | Med | 0.33 | 5.1 | 0.02 | Nov 3, 2023 | A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties. | ||
| CVE-2023-26435 | Med | 0.33 | 5.0 | 0.01 | Jun 20, 2023 | It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system… | ||
| CVE-2023-26431 | Med | 0.33 | 5.0 | 0.01 | Jun 20, 2023 | IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight… | ||
| CVE-2022-29840 | Med | 0.33 | 5.1 | 0.00 | May 10, 2023 | Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the… | ||
| CVE-2023-28155 | Med | 0.33 | 6.1 | 0.01 | Mar 16, 2023 | The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the… | ||
| CVE-2023-24060 | Med | 0.33 | 5.0 | 0.00 | Jan 27, 2023 | Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RSS Feeds or add RSS Feeds can supply an arbitrary hostname (or even the hostname of the Haven server itself). NOTE: this product… | ||
| CVE-2022-39239 | Med | 0.33 | 6.1 | 0.00 | Sep 23, 2022 | netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allowlist by sending specially crafted headers, causing the handler to load and return arbitrary images. Because the response is… | ||
| CVE-2021-34811 | Med | 0.33 | 5.0 | 0.01 | Jun 18, 2021 | Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors. | ||
| CVE-2021-22178 | Med | 0.33 | 5.0 | 0.01 | Mar 24, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration. | ||
| CVE-2020-36232 | Med | 0.33 | 5.0 | 0.01 | Feb 22, 2021 | The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary… | ||
| CVE-2020-15002 | Med | 0.33 | 5.0 | 0.02 | Oct 23, 2020 | OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. | ||
| CVE-2020-12644 | Med | 0.33 | 5.0 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. | ||
| CVE-2020-9427 | Med | 0.33 | 5.0 | 0.01 | Jun 15, 2020 | OX Guard 2.10.3 and earlier allows SSRF. | ||
| CVE-2019-18846 | Med | 0.33 | 5.0 | 0.01 | Feb 21, 2020 | OX App Suite through 7.10.2 allows SSRF. | ||
| CVE-2020-8118 | Med | 0.33 | 5.0 | 0.01 | Feb 4, 2020 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. | ||
| CVE-2018-20497 | Med | 0.33 | 5.0 | 0.01 | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF. | ||
| CVE-2019-1679 | Med | 0.33 | 5.0 | 0.02 | Feb 7, 2019 | A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host.… | ||
| CVE-2026-53508 | Med | 0.32 | — | 0.01 | Aug 31, 2026 | oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from… | ||
| CVE-2026-78277 | Med | 0.32 | 4.9 | 0.00 | Aug 24, 2026 | Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions. | ||
| CVE-2026-65985 | Med | 0.32 | — | 0.00 | Aug 18, 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an… |
- risk 0.33cvss 5.1epss 0.02
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
- risk 0.33cvss 5.0epss 0.01
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system…
- risk 0.33cvss 5.0epss 0.01
IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight…
- risk 0.33cvss 5.1epss 0.00
Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the…
- risk 0.33cvss 6.1epss 0.01
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the…
- risk 0.33cvss 5.0epss 0.00
Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RSS Feeds or add RSS Feeds can supply an arbitrary hostname (or even the hostname of the Haven server itself). NOTE: this product…
- risk 0.33cvss 6.1epss 0.00
netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allowlist by sending specially crafted headers, causing the handler to load and return arbitrary images. Because the response is…
- risk 0.33cvss 5.0epss 0.01
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.
- risk 0.33cvss 5.0epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.
- risk 0.33cvss 5.0epss 0.01
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary…
- risk 0.33cvss 5.0epss 0.02
OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.
- risk 0.33cvss 5.0epss 0.01
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
- risk 0.33cvss 5.0epss 0.01
OX Guard 2.10.3 and earlier allows SSRF.
- risk 0.33cvss 5.0epss 0.01
OX App Suite through 7.10.2 allows SSRF.
- risk 0.33cvss 5.0epss 0.01
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
- risk 0.33cvss 5.0epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
- risk 0.33cvss 5.0epss 0.02
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host.…
- risk 0.32cvss —epss 0.01
oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from…
- risk 0.32cvss 4.9epss 0.00
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
- risk 0.32cvss —epss 0.00
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an…