CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 62 of 73
- CVE-2026-57126HIGHCVSS 8.5EG 8.52026-06-18
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extrac…
- CVE-2026-57211CRITICALCVSS 10.0EG 10.02026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path val…
- CVE-2026-57232LOWCVSS 3.1EG 3.12026-07-31
Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or privat…
- CVE-2026-57303HIGHCVSS 7.1EG 7.12026-06-24
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins …
- CVE-2026-57348HIGHCVSS 7.2EG 7.22026-07-02
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
- CVE-2026-5737MEDIUMCVSS 6.5EG 6.52026-05-28
The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled refer…
- CVE-2026-57372HIGHCVSS 7.2EG 7.22026-07-13
Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.
- CVE-2026-57407HIGHCVSS 7.2EG 7.22026-07-13
Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.
- CVE-2026-57413MEDIUMCVSS 6.4EG 6.42026-07-13
Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.
- CVE-2026-57573HIGHCVSS 8.6EG 8.62026-07-06
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed se…
- CVE-2026-57575MEDIUMCVSS 6.9EG 6.92026-07-10
Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions befor…
- CVE-2026-57627MEDIUMCVSS 4.9EG 4.92026-06-26
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
- CVE-2026-57681MEDIUMCVSS 6.4EG 6.42026-07-02
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
- CVE-2026-5773HIGHCVSS 7.5EG 7.52026-05-13
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection …
- CVE-2026-57862HIGHCVSS 8.5EG 8.52026-07-30
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecima…
- CVE-2026-57866HIGHCVSS 8.8EG 8.82026-09-09
Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the …
- CVE-2026-57894HIGHCVSS 8.5EG 8.52026-07-21
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
- CVE-2026-57940LOWCVSS 2.1EG 2.12026-06-26
HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any vali…
- CVE-2026-57947HIGHCVSS 8.5EG 8.52026-06-29
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshol…
- CVE-2026-57987MEDIUMCVSS 6.5EG 6.52026-07-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-57993HIGHCVSS 7.4EG 7.42026-07-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-5803MEDIUMCVSS 6.3EG 6.32026-04-08
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulati…
- CVE-2026-58189HIGHCVSS 7.5EG 7.52026-07-29
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.…
- CVE-2026-58196MEDIUMCVSS 4.7EG 4.72026-07-15
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer i…
- CVE-2026-58201HIGHCVSS 8.7EG 8.72026-09-15
Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled pa…
- CVE-2026-58278MEDIUMCVSS 5.4EG 5.42026-07-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-58301MEDIUMCVSS 6.5EG 6.52026-08-31
When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vul…
- CVE-2026-58314HIGHCVSS 7.7EG 7.72026-07-21
Two SSRF findings in Gitea 1.26.2
- CVE-2026-5832HIGHCVSS 7.3EG 7.32026-04-09
A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation …
- CVE-2026-58404MEDIUMCVSS 6.8EG 6.82026-07-06
Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alte…
- CVE-2026-58418MEDIUMCVSS 6.5EG 6.52026-07-03
SSRF via HTTP Redirect in Repository Migration
- CVE-2026-58441MEDIUMCVSS 6.3EG 6.32026-07-21
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- CVE-2026-58442MEDIUMCVSS 6.5EG 6.52026-07-21
Repository migration SSRF via multi-answer DNS allow-list bypass
- CVE-2026-58468MEDIUMCVSS 5.5EG 5.52026-07-07
NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request no…
- CVE-2026-58478MEDIUMCVSS 6.5EG 6.52026-07-14
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callba…
- CVE-2026-58485HIGHCVSS 7.1EG 7.12026-09-15
mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled URL through src/index.ts and validates only the li…
- CVE-2026-58501MEDIUMCVSS 5.9EG 5.92026-07-08
Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to …
- CVE-2026-58612HIGHCVSS 7.5EG 7.52026-08-11
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58639MEDIUMCVSS 6.5EG 6.52026-08-11
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-59085CRITICALCVSS 9.1EG 9.12026-08-21
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. U…
- CVE-2026-59095HIGHCVSS 7.7EG 7.72026-07-02
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (im…
- CVE-2026-59101MEDIUMCVSS 5.8EG 5.82026-07-02
AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attac…
- CVE-2026-5921HIGHCVSS 8.9EG 8.92026-04-21
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook r…
- CVE-2026-59221HIGHCVSS 7.7EG 7.72026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths only eight times, allowing a nine-times per…
- CVE-2026-59231MEDIUMCVSS 5.3EG 5.32026-07-31
Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored…
- CVE-2026-59278MEDIUMCVSS 6.5EG 6.52026-08-27
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer …
- CVE-2026-59291MEDIUMCVSS 5.5EG 5.52026-08-27
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
- CVE-2026-5936CRITICALCVSS 9.8EG 9.82026-04-13
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachab…
- CVE-2026-59552HIGHCVSS 7.2EG 7.22026-07-27
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
- CVE-2026-59702CRITICALCVSS 9.3EG 9.32026-07-08
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// U…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →