VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,678)

page 19 of 184
  • CVE-2026-89049CriSep 10, 2026
    risk 0.57cvss 9.9epss 0.01

    A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user…

  • CVE-2026-57866HigSep 9, 2026
    risk 0.57cvss 8.8epss 0.01

    Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path…

  • CVE-2026-86123HigSep 5, 2026
    risk 0.57cvss 8.7epss 0.00

    SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot…

  • CVE-2026-66842HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network…

  • CVE-2026-76851HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted…

  • CVE-2026-50112HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.01

    SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be…

  • CVE-2026-76389HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the…

  • CVE-2026-76351HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to…

  • CVE-2026-55166CriAug 18, 2026
    risk 0.57cvss 9.9epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud…

  • CVE-2026-34884CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

  • CVE-2026-65941HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • CVE-2026-70326HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70324HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-47662HigAug 7, 2026
    risk 0.57cvss —epss 0.00

    Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller with only coarse operation authorities to…

  • CVE-2026-47660HigAug 7, 2026
    risk 0.57cvss —epss 0.01

    Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is…

  • CVE-2026-47659HigAug 7, 2026
    risk 0.57cvss —epss 0.01

    Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async export job ID to supply `file` parameter…

  • CVE-2026-62857HigAug 6, 2026
    risk 0.57cvss —epss 0.00

    Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo…

  • CVE-2026-15732CriAug 6, 2026
    risk 0.57cvss 9.8epss 0.01

    A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

  • CVE-2026-45504HigJun 9, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-46391HigJun 5, 2026
    risk 0.57cvss —epss 0.01

    HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker…