VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 153 of 162
  • CVE-2026-10129HigJun 30, 2026
    risk 0.00cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects…

  • CVE-2026-48285HigJun 30, 2026
    risk 0.00cvss 8.6epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.…

  • CVE-2026-57947HigJun 29, 2026
    risk 0.00cvss 8.5epss 0.00

    Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue…

  • CVE-2026-56285HigJun 29, 2026
    risk 0.00cvss 8.6epss 0.00

    Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the…

  • CVE-2026-13751MedJun 29, 2026
    risk 0.00cvss 4.1epss 0.00

    Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the…

  • CVE-2026-13540MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argument url results in server-side request…

  • CVE-2026-49869CriJun 26, 2026
    risk 0.00cvss 10.0epss 0.01

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather…

  • CVE-2026-56663HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services.…

  • CVE-2026-57627MedJun 26, 2026
    risk 0.00cvss 4.9epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

  • CVE-2026-56026MedJun 26, 2026
    risk 0.00cvss 6.4epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

  • CVE-2026-4339MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform…

  • CVE-2026-57940LowJun 26, 2026
    risk 0.00cvss epss 0.00

    HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with…

  • CVE-2026-2053HigJun 26, 2026
    risk 0.00cvss 8.3epss 0.00

    The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for…

  • CVE-2026-8661MedJun 26, 2026
    risk 0.00cvss 4.8epss 0.00

    Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import)…

  • CVE-2026-12473HigJun 25, 2026
    risk 0.00cvss 8.2epss 0.00

    Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending…

  • CVE-2026-56779MedJun 25, 2026
    risk 0.00cvss 6.4epss 0.00

    MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by supplying unvalidated downloadCallbackUrl and download_url parameters. Attackers with default…

  • CVE-2026-56771HigJun 25, 2026
    risk 0.00cvss 8.5epss 0.00

    NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access…

  • CVE-2026-56769HigJun 25, 2026
    risk 0.00cvss 8.5epss 0.00

    Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs…

  • CVE-2026-55412HigJun 25, 2026
    risk 0.00cvss 8.3epss 0.00

    ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its…

  • CVE-2026-54033HigJun 25, 2026
    risk 0.00cvss 7.7epss 0.00

    LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by setting a baseURL. This URL is used to construct HTTP requests without any SSRF validation — no private…