VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,227)

page 145 of 162
  • CVE-2026-15974MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.

  • CVE-2026-18353HigJul 30, 2026
    risk 0.00cvss epss 0.00

    PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string…

  • CVE-2026-67436HigJul 29, 2026
    risk 0.00cvss epss 0.00

    Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a…

  • CVE-2026-16328HigJul 29, 2026
    risk 0.00cvss 8.6epss 0.00

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul…

  • CVE-2026-6089MedJul 29, 2026
    risk 0.00cvss 4.9epss 0.00

    The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imported JSON files in all versions up to, and including, 2.1.2. This is due to the import_sidebars() function passing user-supplied URLs from imported JSON data to…

  • CVE-2026-4912MedJul 28, 2026
    risk 0.00cvss 4.1epss 0.00

    The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an…

  • CVE-2026-14869HigJul 28, 2026
    risk 0.00cvss 8.6epss 0.00

    The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an…

  • CVE-2026-67173MedJul 28, 2026
    risk 0.00cvss epss 0.00

    Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph data could set an image path to a malicious URI. When a victim rendered the affected graph, the…

  • CVE-2026-65442HigJul 27, 2026
    risk 0.00cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

  • CVE-2026-61953HigJul 27, 2026
    risk 0.00cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

  • CVE-2026-65925MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

  • CVE-2026-65924MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP…

  • CVE-2026-65923MedJul 27, 2026
    risk 0.00cvss 6.8epss 0.00

    A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed…

  • CVE-2026-65618MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.

  • CVE-2026-16481HigJul 27, 2026
    risk 0.00cvss epss 0.00

    A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an…

  • CVE-2026-17552CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). …

  • CVE-2026-17192HigJul 27, 2026
    risk 0.00cvss 8.5epss 0.02

    A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This…

  • CVE-2026-66437MedJul 27, 2026
    risk 0.00cvss 4.9epss 0.00

    Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

  • CVE-2026-65558MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

  • CVE-2026-59552HigJul 27, 2026
    risk 0.00cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.