VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 5 of 182
  • CVE-2026-50775CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.

  • CVE-2026-13739CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.

  • CVE-2026-43995CriMay 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. These tools include (1)…

  • CVE-2026-44335CriMay 8, 2026
    risk 0.64cvss 9.8epss 0.00

    PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32.

  • CVE-2026-8034CriMay 7, 2026
    risk 0.64cvss 9.8epss 0.01

    A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP request library. The hostname…

  • CVE-2026-2286CriMar 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

  • CVE-2026-26137CriMar 19, 2026
    risk 0.64cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-70042CriMar 9, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.

  • CVE-2026-26222CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe…

  • CVE-2026-26339CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

  • CVE-2026-26338CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.

  • CVE-2025-11242CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Side Request Forgery. This issue affects Okulistik: through 21102025.

  • CVE-2025-62616CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.34, in SendDiscordFileBlock, the third-party library aiohttp.ClientSession().get is used directly…

  • CVE-2025-62615CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.34, in RSSFeedBlock, the third-party library urllib.request.urlopen is used directly to access the…

  • CVE-2025-64663CriDec 18, 2025
    risk 0.64cvss 9.9epss 0.01

    Custom Question Answering Elevation of Privilege Vulnerability

  • CVE-2023-53899CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode…

  • CVE-2024-9408CriJul 16, 2025
    risk 0.64cvss 9.8epss 0.00

    In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

  • CVE-2025-45872CriJul 1, 2025
    risk 0.64cvss 9.8epss 0.00

    zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

  • CVE-2025-37090CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A server-side request forgery vulnerability exists in HPE StoreOnce Software.

  • CVE-2024-48590CriMar 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.