VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 28 of 182
  • CVE-2026-81207HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller.…

  • CVE-2026-65818HigSep 3, 2026
    risk 0.55cvss 8.5epss 0.00

    Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70551HigAug 25, 2026
    risk 0.55cvss 8.5epss 0.00

    A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

  • CVE-2026-69543HigAug 20, 2026
    risk 0.55cvss 8.5epss 0.00

    Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-57894HigAug 13, 2026
    risk 0.55cvss 8.5epss 0.00

    Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

  • CVE-2026-18359HigAug 6, 2026
    risk 0.55cvss 8.5epss 0.00

    Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or…

  • CVE-2026-18597HigAug 6, 2026
    risk 0.55cvss 8.5epss 0.00

    The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.

  • CVE-2026-17617HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

  • CVE-2026-9203HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and…

  • CVE-2026-71280HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks).

  • CVE-2026-71271HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in…

  • CVE-2026-54725CriJul 31, 2026
    risk 0.55cvss 9.6epss 0.00

    vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call…

  • CVE-2026-53513CriJul 15, 2026
    risk 0.55cvss 9.6epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when…

  • CVE-2026-11714HigJun 30, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

  • CVE-2026-41461HigApr 23, 2026
    risk 0.55cvss 8.5epss 0.00

    SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated…

  • CVE-2026-35548HigApr 22, 2026
    risk 0.55cvss 8.5epss 0.00

    An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing…

  • CVE-2026-38527HigApr 14, 2026
    risk 0.55cvss 8.5epss 0.00

    A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

  • CVE-2026-5936HigApr 13, 2026
    risk 0.55cvss 8.5epss 0.00

    An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata…

  • CVE-2026-30232CriApr 10, 2026
    risk 0.55cvss 9.6epss 0.00

    Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using…

  • CVE-2026-31818CriApr 3, 2026
    risk 0.55cvss 9.6epss 0.00

    Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the…