CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,680)
page 171 of 184| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65618 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data. | ||
| CVE-2026-17552 | Cri | 0.00 | 9.1 | 0.01 | Jul 27, 2026 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). … | ||
| CVE-2026-17192 | Hig | 0.00 | 8.5 | 0.00 | Jul 27, 2026 | A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This… | ||
| CVE-2026-66437 | Med | 0.00 | 4.9 | 0.00 | Jul 27, 2026 | Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | ||
| CVE-2026-65558 | Med | 0.00 | 5.4 | 0.00 | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | ||
| CVE-2026-59552 | Hig | 0.00 | 7.2 | 0.00 | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | ||
| CVE-2026-17534 | Med | 0.00 | 5.5 | 0.00 | Jul 27, 2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for… | ||
| CVE-2026-17458 | Med | 0.00 | 6.3 | 0.00 | Jul 26, 2026 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to… | ||
| CVE-2026-57106 | Cri | 0.00 | 10.0 | 0.01 | Jul 24, 2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-16870 | Hig | 0.00 | 8.8 | 0.01 | Jul 24, 2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could… | ||
| CVE-2026-56167 | Hig | 0.00 | 8.5 | 0.01 | Jul 24, 2026 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-63313 | Hig | 0.00 | 7.7 | 0.00 | Jul 23, 2026 | 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch… | ||
| CVE-2026-65516 | Hig | 0.00 | 7.2 | 0.00 | Jul 23, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||
| CVE-2026-65496 | Med | 0.00 | 4.4 | 0.00 | Jul 23, 2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | ||
| CVE-2026-65467 | Med | 0.00 | 4.9 | 0.00 | Jul 23, 2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | ||
| CVE-2026-65466 | Med | 0.00 | 4.9 | 0.00 | Jul 23, 2026 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | ||
| CVE-2026-24639 | Med | 0.00 | 4.4 | 0.00 | Jul 23, 2026 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. | ||
| CVE-2026-64873 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | ||
| CVE-2026-64799 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they… | ||
| CVE-2026-65593 | Med | 0.00 | 5.4 | 0.00 | Jul 22, 2026 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL… |
- risk 0.00cvss 6.5epss 0.00
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
- risk 0.00cvss 9.1epss 0.01
Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). …
- risk 0.00cvss 8.5epss 0.00
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This…
- risk 0.00cvss 4.9epss 0.00
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
- risk 0.00cvss 5.4epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
- risk 0.00cvss 7.2epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
- risk 0.00cvss 5.5epss 0.00
Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to…
- risk 0.00cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 8.8epss 0.01
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could…
- risk 0.00cvss 8.5epss 0.01
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 7.7epss 0.00
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch…
- risk 0.00cvss 7.2epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
- risk 0.00cvss 4.4epss 0.00
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
- risk 0.00cvss 4.9epss 0.00
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
- risk 0.00cvss 4.9epss 0.00
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
- risk 0.00cvss 4.4epss 0.00
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they…
- risk 0.00cvss 5.4epss 0.00
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL…