VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 24 of 182
  • CVE-2014-3990CriMar 20, 2018
    risk 0.57cvss 9.8epss 0.06

    The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP…

  • CVE-2018-7667CriMar 5, 2018
    risk 0.57cvss 9.8epss 0.04

    Adminer through 4.3.1 has SSRF via the server parameter.

  • CVE-2018-6186HigFeb 1, 2018
    risk 0.57cvss 8.8epss 0.03

    Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.

  • CVE-2017-0907CriNov 13, 2017
    risk 0.57cvss 9.8epss 0.02

    The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical…

  • CVE-2017-0906CriNov 13, 2017
    risk 0.57cvss 9.8epss 0.02

    The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

  • CVE-2017-0905CriNov 13, 2017
    risk 0.57cvss 9.8epss 0.02

    The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of API keys or other…

  • CVE-2017-1000017HigJul 17, 2017
    risk 0.57cvss 8.8epss 0.01

    phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server

  • CVE-2016-3718MedKEVMay 5, 2016
    risk 0.57cvss 5.5epss 0.77

    The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

  • CVE-2026-81213HigSep 10, 2026
    risk 0.56cvss 8.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

  • CVE-2026-19233HigSep 9, 2026
    risk 0.56cvss —epss 0.01

    CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.

  • CVE-2026-73315HigSep 8, 2026
    risk 0.56cvss 8.6epss 0.00

    XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook…

  • CVE-2026-19305HigSep 4, 2026
    risk 0.56cvss 8.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

  • CVE-2026-85614HigSep 4, 2026
    risk 0.56cvss 8.6epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel…

  • CVE-2026-81091HigAug 27, 2026
    risk 0.56cvss 8.6epss 0.00

    The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __mcp_target parameter and proxied to it…

  • CVE-2026-72848HigAug 20, 2026
    risk 0.56cvss 8.6epss 0.00

    SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child…

  • CVE-2026-66800HigAug 20, 2026
    risk 0.56cvss 8.6epss 0.01

    Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-56677HigAug 17, 2026
    risk 0.56cvss 8.6epss 0.00

    9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback…

  • CVE-2026-72777HigAug 13, 2026
    risk 0.56cvss 8.6epss 0.00

    Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string…

  • CVE-2026-73247HigAug 11, 2026
    risk 0.56cvss 8.6epss 0.00

    Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting…

  • CVE-2026-72581HigAug 10, 2026
    risk 0.56cvss 8.6epss 0.00

    A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url…