CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,227)
page 146 of 162| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-17534 | Med | 0.00 | 5.5 | 0.00 | Jul 27, 2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for… | ||
| CVE-2025-15662 | Hig | 0.00 | 8.6 | 0.00 | Jul 27, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files… | ||
| CVE-2026-17458 | Med | 0.00 | 6.3 | 0.00 | Jul 26, 2026 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to… | ||
| CVE-2026-57106 | Cri | 0.00 | 10.0 | 0.01 | Jul 24, 2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-16870 | Hig | 0.00 | 8.8 | 0.00 | Jul 24, 2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could… | ||
| CVE-2026-56167 | Hig | 0.00 | 8.5 | 0.00 | Jul 24, 2026 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-63313 | Hig | 0.00 | 7.7 | 0.00 | Jul 23, 2026 | 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch… | ||
| CVE-2026-65516 | Hig | 0.00 | 7.2 | 0.00 | Jul 23, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||
| CVE-2026-65496 | Med | 0.00 | 4.4 | 0.00 | Jul 23, 2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | ||
| CVE-2026-65467 | Med | 0.00 | 4.9 | 0.00 | Jul 23, 2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | ||
| CVE-2026-65466 | Med | 0.00 | 4.9 | 0.00 | Jul 23, 2026 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | ||
| CVE-2026-24639 | Med | 0.00 | 4.4 | 0.00 | Jul 23, 2026 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. | ||
| CVE-2026-64873 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | ||
| CVE-2026-64799 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they… | ||
| CVE-2026-65593 | Med | 0.00 | 5.4 | 0.00 | Jul 22, 2026 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL… | ||
| CVE-2026-65318 | Hig | 0.00 | 8.6 | 0.00 | Jul 21, 2026 | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint.… | ||
| CVE-2026-65317 | Hig | 0.00 | 8.6 | 0.00 | Jul 21, 2026 | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and… | ||
| CVE-2026-65057 | Cri | 0.00 | 9.3 | 0.00 | Jul 21, 2026 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted… | ||
| CVE-2026-65056 | Hig | 0.00 | 8.2 | 0.00 | Jul 21, 2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering… | ||
| CVE-2026-64626 | Med | 0.00 | 6.4 | 0.00 | Jul 20, 2026 | AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that… |
- risk 0.00cvss 5.5epss 0.00
Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for…
- risk 0.00cvss 8.6epss 0.00
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to…
- risk 0.00cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 8.8epss 0.00
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could…
- risk 0.00cvss 8.5epss 0.00
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 7.7epss 0.00
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch…
- risk 0.00cvss 7.2epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
- risk 0.00cvss 4.4epss 0.00
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
- risk 0.00cvss 4.9epss 0.00
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
- risk 0.00cvss 4.9epss 0.00
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
- risk 0.00cvss 4.4epss 0.00
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they…
- risk 0.00cvss 5.4epss 0.00
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL…
- risk 0.00cvss 8.6epss 0.00
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint.…
- risk 0.00cvss 8.6epss 0.00
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and…
- risk 0.00cvss 9.3epss 0.00
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted…
- risk 0.00cvss 8.2epss 0.00
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering…
- risk 0.00cvss 6.4epss 0.00
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that…