CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,621)
page 40 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-45394 | Hig | 0.50 | 8.8 | 0.02 | Jan 18, 2022 | An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious tag in the converted HTML document. | ||
| CVE-2021-41084 | Hig | 0.50 | 8.7 | 0.01 | Sep 21, 2021 | http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header values… | ||
| CVE-2021-22255 | Hig | 0.50 | 7.7 | 0.01 | Aug 20, 2021 | SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address. | ||
| CVE-2021-37711 | Hig | 0.50 | 8.8 | 0.01 | Aug 16, 2021 | Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. | ||
| CVE-2021-33184 | Hig | 0.50 | 7.7 | 0.01 | Jun 1, 2021 | Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors. | ||
| CVE-2019-15033 | Hig | 0.50 | 7.7 | 0.01 | Sep 19, 2019 | Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring. | ||
| CVE-2019-8451 | Med | 0.50 | 6.5 | 0.94 | Sep 11, 2019 | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class. | ||
| CVE-2017-3164 | Hig | 0.50 | 7.5 | 0.18 | Mar 8, 2019 | Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL. | ||
| CVE-2017-7566 | Hig | 0.50 | 7.7 | 0.02 | Apr 6, 2017 | MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism. | ||
| CVE-2016-4374 | Hig | 0.50 | 7.7 | 0.02 | Aug 8, 2016 | HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unspecified vectors. | ||
| CVE-2026-85917 | Hig | 0.49 | 7.5 | 0.01 | Sep 17, 2026 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-92576 | Hig | 0.49 | 8.6 | 0.00 | Sep 16, 2026 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata… | ||
| CVE-2026-54628 | Hig | 0.49 | 8.6 | 0.00 | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A… | ||
| CVE-2026-81265 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5. | ||
| CVE-2026-88056 | Hig | 0.49 | — | 0.00 | Sep 10, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs… | ||
| CVE-2026-66304 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-86119 | Hig | 0.49 | 8.6 | 0.00 | Sep 5, 2026 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud… | ||
| CVE-2026-85699 | Hig | 0.49 | 7.5 | 0.00 | Sep 4, 2026 | jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata… | ||
| CVE-2026-85691 | Hig | 0.49 | 7.5 | 0.00 | Sep 4, 2026 | MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses… | ||
| CVE-2026-85686 | Hig | 0.49 | 7.5 | 0.00 | Sep 4, 2026 | ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters… |
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious tag in the converted HTML document.
- risk 0.50cvss 8.7epss 0.01
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header values…
- risk 0.50cvss 7.7epss 0.01
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.
- risk 0.50cvss 8.8epss 0.01
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
- risk 0.50cvss 7.7epss 0.01
Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.
- risk 0.50cvss 7.7epss 0.01
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.
- risk 0.50cvss 6.5epss 0.94
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
- risk 0.50cvss 7.5epss 0.18
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
- risk 0.50cvss 7.7epss 0.02
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
- risk 0.50cvss 7.7epss 0.02
HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unspecified vectors.
- risk 0.49cvss 7.5epss 0.01
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
- risk 0.49cvss 8.6epss 0.00
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata…
- risk 0.49cvss 8.6epss 0.00
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A…
- risk 0.49cvss 7.5epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5.
- risk 0.49cvss —epss 0.00
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs…
- risk 0.49cvss 7.5epss 0.01
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 8.6epss 0.00
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud…
- risk 0.49cvss 7.5epss 0.00
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata…
- risk 0.49cvss 7.5epss 0.00
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses…
- risk 0.49cvss 7.5epss 0.00
ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters…