VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 163 of 184
  • CVE-2024-43371MedAug 21, 2024
    risk 0.22cvss 4.5epss 0.00

    CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that work by downloading the contents of local or remote files in order to perform some…

  • CVE-2023-47635MedFeb 20, 2024
    risk 0.22cvss 4.5epss 0.00

    Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionnaire templates preview. The issue does not imply a serious security thread as you need to have…

  • CVE-2023-23684MedNov 13, 2023
    risk 0.22cvss 4.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.

  • CVE-2022-44730MedAug 22, 2023
    risk 0.22cvss 4.4epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.

  • CVE-2026-102244MedSep 29, 2026
    risk 0.21cvss 4.3epss 0.00

    A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The…

  • CVE-2026-101087MedSep 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix…

  • CVE-2026-94028MedSep 20, 2026
    risk 0.21cvss 4.3epss 0.00

    A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead…

  • CVE-2026-92569MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trigger outbound GET requests to internal…

  • CVE-2026-90446MedSep 11, 2026
    risk 0.21cvss 4.3epss 0.00

    An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an…

  • CVE-2026-86503LowSep 7, 2026
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

  • CVE-2026-83744MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the argument notes leads to…

  • CVE-2026-77352MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to internal/link-local addresses, by setting…

  • CVE-2026-18545MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2026-54492MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php does not apply the SafeUrl validation used…

  • CVE-2026-45123MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in…

  • CVE-2026-49856MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit…

  • CVE-2026-46548MedJun 23, 2026
    risk 0.21cvss 4.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because httpAgent / httpsAgent were passed as part of the…

  • CVE-2026-44502MedMay 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. The original validation logic parsed webhook URLs with Python’s urllib.parse.urlparse, then sent the request…

  • CVE-2026-43936MedMay 26, 2026
    risk 0.21cvss 4.3epss 0.00

    e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "Media Manager" on the administrator screen. This vulnerability is fixed in 2.3.4.

  • CVE-2026-45347MedMay 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side request forgery (SSRF) via the PDF generate function. In the PDF export, user inputs are interpreted as HTML and embedded into the…