VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 76 of 182
  • CVE-2026-19050MedAug 12, 2026
    risk 0.42cvss 6.4epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the…

  • CVE-2026-65813MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-58639MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-72598MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by registering a webhook URL pointing to an internal host. The webhook registration endpoint validates…

  • CVE-2026-72597MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an…

  • CVE-2026-72560MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default…

  • CVE-2026-16637MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

  • CVE-2026-45573MedAug 6, 2026
    risk 0.42cvss 6.4epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint without validating that it belongs to an…

  • CVE-2026-34966HigAug 5, 2026
    risk 0.42cvss 7.6epss 0.00

    Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext.…

  • CVE-2026-55524HigAug 5, 2026
    risk 0.42cvss 7.5epss 0.00

    PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinations. The check resolves the…

  • CVE-2026-7657MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.

  • CVE-2026-71244MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server,…

  • CVE-2026-71208MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specified Kubernetes API endpoint, which is…

  • CVE-2026-66901HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe…

  • CVE-2026-67315HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies,…

  • CVE-2026-52371MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

  • CVE-2026-58189HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to…

  • CVE-2026-55391HigJul 28, 2026
    risk 0.42cvss 7.5epss 0.00

    datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in…

  • CVE-2026-13192MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and…

  • CVE-2026-46556MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints,…