VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 41 of 182
  • CVE-2026-85675HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server…

  • CVE-2026-85673HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and…

  • CVE-2026-85666HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values)…

  • CVE-2026-85612HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and…

  • CVE-2026-85609HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parameter to fetchWithRedirects()…

  • CVE-2026-85180HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET…

  • CVE-2026-81889HigAug 31, 2026
    risk 0.49cvss 8.6epss 0.00

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates…

  • CVE-2026-82638HigAug 30, 2026
    risk 0.49cvss 7.5epss 0.00

    jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal…

  • CVE-2026-82268HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue…

  • CVE-2026-81093HigAug 27, 2026
    risk 0.49cvss 8.6epss 0.00

    The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from src/utils/generic.ts, which confirmed the string began with an http or https…

  • CVE-2026-52776HigAug 26, 2026
    risk 0.49cvss —epss 0.00

    Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach…

  • CVE-2026-77775HigAug 21, 2026
    risk 0.49cvss 8.6epss 0.00

    Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname,…

  • CVE-2026-45741HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.01

    Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec0::/10 deprecated site-local prefix,…

  • CVE-2026-75856HigAug 18, 2026
    risk 0.49cvss 8.6epss 0.00

    CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing…

  • CVE-2026-59765HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

  • CVE-2026-72606HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to…

  • CVE-2026-72552HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without…

  • CVE-2026-47618HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47617HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47616HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.