VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 152 of 162
  • CVE-2026-57987MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-22874CriJul 3, 2026
    risk 0.00cvss 9.6epss 0.01

    Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

  • CVE-2026-11397MedJul 3, 2026
    risk 0.00cvss 5.5epss 0.00

    The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_remote_get() (which correctly blocks…

  • CVE-2026-57100CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-45499CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-59101MedJul 2, 2026
    risk 0.00cvss 5.8epss 0.00

    AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST…

  • CVE-2026-59095HigJul 2, 2026
    risk 0.00cvss 7.7epss 0.00

    LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update…

  • CVE-2026-55115CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

  • CVE-2026-55113HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.

  • CVE-2026-54401HigJul 2, 2026
    risk 0.00cvss 7.7epss 0.00

    A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.

  • CVE-2026-57681MedJul 2, 2026
    risk 0.00cvss 6.4epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.

  • CVE-2026-57348HigJul 2, 2026
    risk 0.00cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.

  • CVE-2026-14336HigJul 2, 2026
    risk 0.00cvss 8.2epss 0.00

    PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as …

  • CVE-2026-24242HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-56399MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal…

  • CVE-2025-36324MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2026-13773MedJun 30, 2026
    risk 0.00cvss 6.0epss 0.03

    IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink…

  • CVE-2026-11546HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.

  • CVE-2026-10564HigJun 30, 2026
    risk 0.00cvss 8.2epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An…

  • CVE-2026-10546HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding.