VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 35 of 182
  • CVE-2025-67647CriJan 15, 2026
    risk 0.52cvss 9.1epss 0.01

    SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability…

  • CVE-2025-64522CriNov 10, 2025
    risk 0.52cvss 9.1epss 0.00

    Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata…

  • CVE-2025-53371CriJul 10, 2025
    risk 0.52cvss 9.1epss 0.00

    DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and file_get_contents to arbitrary URLs set via $wgDiscordIncomingWebhookUrl and…

  • CVE-2025-6087CriJun 16, 2025
    risk 0.52cvss 9.1epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the…

  • CVE-2024-45479CriJan 21, 2025
    risk 0.52cvss 9.1epss 0.01

    SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

  • CVE-2024-47883CriOct 24, 2024
    risk 0.52cvss 9.1epss 0.02

    The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or templates. This works: "opening a connection" to these…

  • CVE-2024-47008HigOct 8, 2024
    risk 0.52cvss 7.5epss 0.47

    Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-47066CriSep 23, 2024
    risk 0.52cvss 9.0epss 0.12

    Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL…

  • CVE-2024-29736CriJul 19, 2024
    risk 0.52cvss 9.1epss 0.01

    A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

  • CVE-2024-4325HigJun 6, 2024
    risk 0.52cvss 8.6epss 0.37

    A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. The vulnerability arises when the `path` value, obtained from the user and expected to be a…

  • CVE-2024-25738CriMay 22, 2024
    risk 0.52cvss 9.1epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files to gain access to the administrator panel and achieve Remote Code…

  • CVE-2024-31461CriApr 10, 2024
    risk 0.52cvss 9.1epss 0.01

    Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may allow an attacker to send arbitrary requests from the server hosting the application, potentially leading to unauthorized access to…

  • CVE-2024-27620HigApr 6, 2024
    risk 0.52cvss 7.5epss 0.02

    An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

  • CVE-2024-22205CriJan 23, 2024
    risk 0.52cvss 9.1epss 0.01

    Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the `location` variable and passes it to the `send` method which sends a `GET` request on lines 339-343 in `request.py,` which leads…

  • CVE-2024-22203CriJan 23, 2024
    risk 0.52cvss 9.1epss 0.01

    Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` variables and passes them to the `send` method which sends a GET request on lines 339-343 in…

  • CVE-2023-48240CriNov 20, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for…

  • CVE-2023-36661HigJun 25, 2023
    risk 0.52cvss 7.5epss 0.03

    Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

  • CVE-2023-27159HigMar 31, 2023
    risk 0.52cvss 7.5epss 0.36

    Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

  • CVE-2022-2900CriSep 14, 2022
    risk 0.52cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.

  • CVE-2022-0768CriFeb 28, 2022
    risk 0.52cvss 9.1epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.