VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 78 of 185
  • CVE-2026-82243HigAug 28, 2026
    risk 0.42cvss 7.6epss 0.00

    Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making…

  • CVE-2026-81678HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the…

  • CVE-2026-59278MedAug 27, 2026
    risk 0.42cvss 6.5epss 0.00

    JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type…

  • CVE-2026-79717MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or…

  • CVE-2026-55525HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target…

  • CVE-2026-78682HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.00

    NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler…

  • CVE-2026-75975HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.00

    fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6…

  • CVE-2026-75899HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.00

    fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different…

  • CVE-2026-61704HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.01

    Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback…

  • CVE-2026-77085MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On instances with…

  • CVE-2026-59765HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.01

    SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

  • CVE-2026-58442MedAug 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Repository migration SSRF via multi-answer DNS allow-list bypass

  • CVE-2026-73264HigAug 12, 2026
    risk 0.42cvss 7.6epss 0.00

    Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST…

  • CVE-2026-19050MedAug 12, 2026
    risk 0.42cvss 6.4epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the…

  • CVE-2026-65813MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-58639MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-72598MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by registering a webhook URL pointing to an internal host. The webhook registration endpoint validates…

  • CVE-2026-72597MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an…

  • CVE-2026-72560MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default…

  • CVE-2026-16637MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.