CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,680)
page 170 of 184| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41321 | — | Low | 0.07 | 2.2 | 0.00 | Apr 24, 2026 | @astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare… | |
| CVE-2024-27098 | Med | 0.03 | 6.4 | 0.36 | Mar 18, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13. | ||
| CVE-2024-7959 | 0.02 | — | 0.24 | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||
| CVE-2022-24856 | Cri | 0.01 | 9.1 | 0.10 | May 17, 2022 | FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the… | ||
| CVE-2022-1713 | Hig | 0.01 | 7.5 | 0.10 | May 16, 2022 | SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information. | ||
| CVE-2025-24979 | 0.00 | — | — | Sep 9, 2026 | ### Summary Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces… | |||
| CVE-2026-66415 | Hig | 0.00 | 8.5 | 0.00 | Jul 30, 2026 | Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path… | ||
| CVE-2026-15974 | Med | 0.00 | 6.5 | 0.00 | Jul 30, 2026 | SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services. | ||
| CVE-2026-18353 | Hig | 0.00 | — | 0.00 | Jul 30, 2026 | PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string… | ||
| CVE-2026-67436 | Hig | 0.00 | — | 0.00 | Jul 29, 2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a… | ||
| CVE-2026-16328 | Hig | 0.00 | 8.6 | 0.00 | Jul 29, 2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul… | ||
| CVE-2026-6089 | Med | 0.00 | 4.9 | 0.00 | Jul 29, 2026 | The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imported JSON files in all versions up to, and including, 2.1.2. This is due to the import_sidebars() function passing user-supplied URLs from imported JSON data to… | ||
| CVE-2026-4912 | Med | 0.00 | 4.1 | 0.00 | Jul 28, 2026 | The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an… | ||
| CVE-2026-14869 | Hig | 0.00 | 8.6 | 0.00 | Jul 28, 2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an… | ||
| CVE-2026-67173 | Med | 0.00 | — | 0.00 | Jul 28, 2026 | Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph data could set an image path to a malicious URI. When a victim rendered the affected graph, the… | ||
| CVE-2026-65442 | Hig | 0.00 | 7.2 | 0.01 | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. | ||
| CVE-2026-61953 | Hig | 0.00 | 7.2 | 0.00 | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | ||
| CVE-2026-65925 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. | ||
| CVE-2026-65924 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP… | ||
| CVE-2026-65923 | Med | 0.00 | 6.8 | 0.00 | Jul 27, 2026 | A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed… |
- risk 0.07cvss 2.2epss 0.00
@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare…
- risk 0.03cvss 6.4epss 0.36
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13.
- CVE-2024-7959Mar 20, 2025risk 0.02cvss —epss 0.24
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.01cvss 9.1epss 0.10
FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the…
- risk 0.01cvss 7.5epss 0.10
SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.
- CVE-2025-24979Sep 9, 2026risk 0.00cvss —epss —
### Summary Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces…
- risk 0.00cvss 8.5epss 0.00
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path…
- risk 0.00cvss 6.5epss 0.00
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.
- risk 0.00cvss —epss 0.00
PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string…
- risk 0.00cvss —epss 0.00
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a…
- risk 0.00cvss 8.6epss 0.00
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul…
- risk 0.00cvss 4.9epss 0.00
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imported JSON files in all versions up to, and including, 2.1.2. This is due to the import_sidebars() function passing user-supplied URLs from imported JSON data to…
- risk 0.00cvss 4.1epss 0.00
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an…
- risk 0.00cvss 8.6epss 0.00
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an…
- risk 0.00cvss —epss 0.00
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph data could set an image path to a malicious URI. When a victim rendered the affected graph, the…
- risk 0.00cvss 7.2epss 0.01
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
- risk 0.00cvss 7.2epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
- risk 0.00cvss 6.5epss 0.00
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
- risk 0.00cvss 6.5epss 0.00
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP…
- risk 0.00cvss 6.8epss 0.00
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed…