VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 36 of 182
  • CVE-2021-39935MedKEVDec 13, 2021
    risk 0.52cvss 6.8epss 0.36

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

  • CVE-2021-36043HigSep 1, 2021
    risk 0.52cvss 8.0epss 0.02

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be…

  • CVE-2021-30108CriMay 24, 2021
    risk 0.52cvss 9.1epss 0.01

    Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.

  • CVE-2021-30492criApr 29, 2021
    risk 0.52cvss —epss 0.00

    ### Impact Lack of input validation of the Zendesk subdomain could expose users of the library to Server Side Request Forgery (SSRF). ### Resolution Validate the provided Zendesk subdomain to be a valid subdomain in: * getAuthUrl * getAccessToken

  • CVE-2020-15152CriAug 17, 2020
    risk 0.52cvss 9.1epss 0.02

    ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the…

  • CVE-2018-20228HigDec 19, 2018
    risk 0.52cvss 8.0epss 0.00

    Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.

  • CVE-2017-1000139HigNov 3, 2017
    risk 0.52cvss 8.0epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

  • CVE-2025-61916HigJan 5, 2026
    risk 0.51cvss 7.9epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into…

  • CVE-2025-63408HigNov 18, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands.

  • CVE-2025-64178HigNov 6, 2025
    risk 0.51cvss —epss 0.00

    Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the server, accepted a URL parameter that was directly passed to the cache package, which downloaded the poster from this URL. This…

  • CVE-2025-34021HigJun 20, 2025
    risk 0.51cvss —epss 0.01

    A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The application fails to validate…

  • CVE-2025-22399HigFeb 11, 2025
    risk 0.51cvss 7.9epss 0.00

    Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery

  • CVE-2023-42361HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.01

    Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.

  • CVE-2022-3841HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is…

  • CVE-2022-25026HigJan 12, 2023
    risk 0.51cvss 7.5epss 0.24

    A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.

  • CVE-2022-22993HigJan 28, 2022
    risk 0.51cvss 7.8epss 0.01

    A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.

  • CVE-2018-15657HigFeb 5, 2019
    risk 0.51cvss 7.3epss 0.01

    An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.

  • CVE-2026-58201HigSep 15, 2026
    risk 0.50cvss —epss 0.00

    Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com…

  • CVE-2026-91923HigSep 15, 2026
    risk 0.50cvss 7.7epss 0.00

    KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services…

  • CVE-2026-87084HigSep 9, 2026
    risk 0.50cvss 7.7epss 0.00

    Tanium addressed a server-side request forgery vulnerability in Enforce.