VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,679)

page 177 of 184
  • CVE-2026-14336HigJul 2, 2026
    risk 0.00cvss 8.2epss 0.00

    PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as …

  • CVE-2026-24242HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-56399MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal…

  • CVE-2026-13773MedJun 30, 2026
    risk 0.00cvss 6.0epss 0.06

    IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink…

  • CVE-2026-11546HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.

  • CVE-2026-10564HigJun 30, 2026
    risk 0.00cvss 8.2epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An…

  • CVE-2026-10546HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding.

  • CVE-2026-10129HigJun 30, 2026
    risk 0.00cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects…

  • CVE-2026-57947HigJun 29, 2026
    risk 0.00cvss 8.5epss 0.00

    Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue…

  • CVE-2026-56285HigJun 29, 2026
    risk 0.00cvss 8.6epss 0.00

    Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the…

  • CVE-2026-13751MedJun 29, 2026
    risk 0.00cvss 4.1epss 0.00

    Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the…

  • CVE-2026-13540MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argument url results in server-side request…

  • CVE-2026-56663HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services.…

  • CVE-2026-57627MedJun 26, 2026
    risk 0.00cvss 4.9epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

  • CVE-2026-56026MedJun 26, 2026
    risk 0.00cvss 6.4epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

  • CVE-2026-4339MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform…

  • CVE-2026-57940LowJun 26, 2026
    risk 0.00cvss —epss 0.00

    HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with…

  • CVE-2026-2053HigJun 26, 2026
    risk 0.00cvss 8.3epss 0.00

    The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for…

  • CVE-2026-8661MedJun 26, 2026
    risk 0.00cvss 4.8epss 0.00

    Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import)…

  • CVE-2026-12473HigJun 25, 2026
    risk 0.00cvss 8.2epss 0.00

    Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending…