VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 155 of 184
  • CVE-2018-1000067MedFeb 16, 2018
    risk 0.28cvss 5.3epss 0.02

    An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

  • CVE-2017-18036MedFeb 2, 2018
    risk 0.28cvss 4.3epss 0.01

    The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability.

  • CVE-2026-100601MedSep 26, 2026
    risk 0.27cvss 5.3epss 0.00

    ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not…

  • CVE-2026-77249MedSep 22, 2026
    risk 0.27cvss 5.3epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead of the fetcher's protected session. A caller-controlled public Jira…

  • CVE-2026-16542MedSep 20, 2026
    risk 0.27cvss 4.1epss 0.00

    The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.

  • CVE-2026-54918MedSep 17, 2026
    risk 0.27cvss 5.3epss 0.00

    NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant that an unauthenticated pull-request author…

  • CVE-2026-59823MedSep 16, 2026
    risk 0.27cvss —epss 0.00

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_request_body_safe, which blocks top-level…

  • CVE-2026-76559MedSep 16, 2026
    risk 0.27cvss 4.1epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site issue requests to internal hosts and…

  • CVE-2026-44202MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token.…

  • CVE-2026-49865MedSep 11, 2026
    risk 0.27cvss —epss 0.00

    Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as…

  • CVE-2026-88896MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recognize IPv6 transition addresses…

  • CVE-2026-54048MedSep 9, 2026
    risk 0.27cvss 5.3epss 0.01

    Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be…

  • CVE-2026-83543MedSep 5, 2026
    risk 0.27cvss 4.1epss 0.00

    The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.

  • CVE-2026-75036MedSep 3, 2026
    risk 0.27cvss —epss 0.00

    A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource…

  • CVE-2026-74768MedSep 3, 2026
    risk 0.27cvss 4.1epss 0.00

    Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2026-73474MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.

  • CVE-2026-84175MedSep 2, 2026
    risk 0.27cvss —epss 0.00

    In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the…

  • CVE-2026-84697MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in…

  • CVE-2026-82476MedAug 29, 2026
    risk 0.27cvss 5.3epss 0.00

    Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata…

  • CVE-2026-5096MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload…