VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 149 of 162
  • CVE-2026-15750MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request…

  • CVE-2026-61520HigJul 14, 2026
    risk 0.00cvss 7.7epss 0.00

    Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image…

  • CVE-2026-24234MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

  • CVE-2026-15643HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server…

  • CVE-2026-48259CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests,…

  • CVE-2026-55051MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  • CVE-2026-14646MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server…

  • CVE-2026-14645MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations…

  • CVE-2026-7494MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts.…

  • CVE-2026-58478MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin…

  • CVE-2026-15183CriJul 14, 2026
    risk 0.00cvss epss 0.00

    Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to…

  • CVE-2026-15668MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/tools/web.go of the component web Tool. The manipulation of the argument url leads to server-side request forgery. The attack can be…

  • CVE-2026-15628MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in…

  • CVE-2026-15624MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url…

  • CVE-2026-15620MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed…

  • CVE-2026-15619MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component IPv4 Handler. This manipulation of the argument url causes server-side request forgery. The attack can be initiated…

  • CVE-2026-62242HigJul 13, 2026
    risk 0.00cvss 8.6epss 0.00

    Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata…

  • CVE-2026-62240HigJul 13, 2026
    risk 0.00cvss 7.4epss 0.00

    CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect…

  • CVE-2026-62197HigJul 13, 2026
    risk 0.00cvss 8.5epss 0.00

    OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.

  • CVE-2026-49969HigJul 13, 2026
    risk 0.00cvss 7.4epss 0.00

    Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). Attackers can…