VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 157 of 184
  • CVE-2024-4561MedMay 14, 2024
    risk 0.27cvss 4.2epss 0.00

    In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.

  • CVE-2023-46207MedNov 13, 2023
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.

  • CVE-2023-31219MedNov 13, 2023
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.

  • CVE-2022-48477MedApr 24, 2023
    risk 0.27cvss 4.1epss 0.00

    In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing

  • CVE-2023-24622MedJan 30, 2023
    risk 0.27cvss 5.3epss 0.01

    isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.

  • CVE-2022-46830MedDec 8, 2022
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.

  • CVE-2022-27622MedOct 25, 2022
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote authenticated users to access intranet resources via unspecified vectors.

  • CVE-2019-6512MedMay 14, 2019
    risk 0.27cvss 4.1epss 0.01

    An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file://…

  • CVE-2018-13404MedFeb 13, 2019
    risk 0.27cvss 4.1epss 0.01

    The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before…

  • CVE-2026-102879MedSep 29, 2026
    risk 0.26cvss 5.0epss 0.00

    ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud…

  • CVE-2026-100863MedSep 27, 2026
    risk 0.26cvss 5.0epss 0.00

    Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get,…

  • CVE-2026-100861MedSep 27, 2026
    risk 0.26cvss 5.0epss 0.00

    heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowing authenticated users to bypass SSRF protections. Attackers can configure credentials pointing to loopback, private, or cloud-metadata addresses and read…

  • CVE-2026-54546MedSep 17, 2026
    risk 0.26cvss 5.0epss 0.00

    CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/routes/basemap.ts to fetch(url) without…

  • CVE-2026-92932MedSep 17, 2026
    risk 0.26cvss —epss 0.00

    In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http://') === 0 ||…

  • CVE-2026-88892MedSep 10, 2026
    risk 0.26cvss 5.0epss 0.00

    In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile calls fetch() on config.fileUrl, which is…

  • CVE-2026-88001MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when AIOHTTP_CLIENT_ALLOW_REDIRECTS was enabled.…

  • CVE-2026-86735MedSep 8, 2026
    risk 0.26cvss 5.0epss 0.00

    snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4,…

  • CVE-2026-86122MedSep 5, 2026
    risk 0.26cvss 5.0epss 0.00

    Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate…

  • CVE-2026-77067MedAug 20, 2026
    risk 0.26cvss 5.0epss 0.00

    The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues…

  • CVE-2026-77066MedAug 20, 2026
    risk 0.26cvss 5.0epss 0.00

    The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved…