VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,227)

page 144 of 162
  • CVE-2026-44286LowMay 8, 2026
    risk 0.08cvss epss 0.00

    FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows attackers (or authenticated users with App editing privileges) to send arbitrary HTTP requests to internal/private network addresses.…

  • CVE-2026-48978LowJul 17, 2026
    risk 0.07cvss epss 0.00

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such…

  • CVE-2026-58196lowJul 15, 2026
    risk 0.07cvss epss

    # Security Advisory: SSRF in remote MCP server authentication discovery **Severity:** High. **CWE:** CWE-918. **Affected:** ToolHive through the latest release v0.29.3 and current `main` (HEAD b672d82f, 2026-06-12; re-verified 2026-06-14). `FetchResourceMetadata` and the…

  • CVE-2026-54450lowJul 15, 2026
    risk 0.07cvss epss

    ## Summary ToolHive's hand-rolled private/reserved-IP SSRF guard (`networking.IsPrivateIP` in `pkg/networking/utilities.go`) does not recognize the IPv6 **NAT64** address ranges — the well-known prefix `64:ff9b::/96` (RFC 6052) and the RFC 8215 local-use prefix…

  • CVE-2026-41321LowApr 24, 2026
    risk 0.07cvss 2.2epss 0.00

    @astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare…

  • CVE-2020-25820MedOct 21, 2020
    risk 0.04cvss 6.5epss 0.10

    BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.

  • CVE-2024-27098MedMar 18, 2024
    risk 0.03cvss 6.4epss 0.36

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13.

  • CVE-2018-25031MedMar 11, 2022
    risk 0.03cvss 4.3epss 0.42

    Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3.…

  • CVE-2024-7959Mar 20, 2025
    risk 0.02cvss epss 0.24

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2021-21287HigFeb 1, 2021
    risk 0.02cvss 7.7epss 0.25

    MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. The target application may have functionality for importing data from a URL, publishing data…

  • CVE-2026-48332HigJul 14, 2026
    risk 0.01cvss 7.7epss 0.11

    ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does…

  • CVE-2022-24856CriMay 17, 2022
    risk 0.01cvss 9.1epss 0.10

    FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the…

  • CVE-2022-1713HigMay 16, 2022
    risk 0.01cvss 7.5epss 0.09

    SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

  • CVE-2026-53708Aug 14, 2026
    risk 0.00cvss epss

    ## Summary The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a…

  • CVE-2026-16536MedAug 4, 2026
    risk 0.00cvss 5.3epss 0.00

    The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response…

  • CVE-2026-14939MedAug 4, 2026
    risk 0.00cvss 6.8epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata…

  • CVE-2026-10526MedAug 4, 2026
    risk 0.00cvss 5.8epss 0.00

    The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core…

  • CVE-2026-18736MedAug 3, 2026
    risk 0.00cvss 5.0epss 0.00

    Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs…

  • CVE-2026-52371MedJul 31, 2026
    risk 0.00cvss 6.5epss 0.00

    A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

  • CVE-2026-66415HigJul 30, 2026
    risk 0.00cvss 8.5epss 0.00

    Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path…