CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 64 of 73
- CVE-2026-63088HIGHCVSS 8.6EG 8.62026-07-16
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_bla…
- CVE-2026-63096MEDIUMCVSS 5.8EG 5.82026-07-17
Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName par…
- CVE-2026-63107HIGHCVSS 7.7EG 7.72026-07-20
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipula…
- CVE-2026-63306HIGHCVSS 8.6EG 8.62026-07-16
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enum…
- CVE-2026-63311MEDIUMCVSS 5.3EG 5.32026-08-22
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during soc…
- CVE-2026-63313HIGHCVSS 7.7EG 7.72026-07-23
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina…
- CVE-2026-6333LOWCVSS 3.5EG 3.52026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-…
- CVE-2026-63443HIGHCVSS 8.3EG 8.32026-09-15
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected r…
- CVE-2026-63464HIGHCVSS 7.7EG 7.72026-09-04
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/web…
- CVE-2026-63642MEDIUMCVSS 6.3EG 6.32026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed …
- CVE-2026-63643MEDIUMCVSS 6.3EG 6.32026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through …
- CVE-2026-63730MEDIUMCVSS 5.0EG 5.02026-07-20
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the …
- CVE-2026-63731HIGHCVSS 7.7EG 7.72026-07-20
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse pro…
- CVE-2026-63736MEDIUMCVSS 4.1EG 4.12026-07-20
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role attacker can point an acc…
- CVE-2026-63743MEDIUMCVSS 6.4EG 6.42026-07-20
SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a deni…
- CVE-2026-63744MEDIUMCVSS 4.1EG 4.12026-07-20
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS…
- CVE-2026-63764CRITICALCVSS 8.6EG 9.32026-07-21
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original URL…
- CVE-2026-63769HIGHCVSS 7.7EG 7.72026-07-20
Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe interna…
- CVE-2026-6394MEDIUMCVSS 5.4EG 5.42026-05-20
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepti…
- CVE-2026-64626MEDIUMCVSS 6.4EG 6.42026-07-20
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated att…
- CVE-2026-64645MEDIUMCVSS 6.1EG 6.12026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled i…
- CVE-2026-64649MEDIUMCVSS 6.5EG 6.52026-07-22
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbo…
- CVE-2026-64799HIGHCVSS 7.5EG 7.52026-07-23
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save re…
- CVE-2026-64849CRITICALCVSS 9.3EG 9.3⚠ KEV2026-08-17
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/…
- CVE-2026-64870MEDIUMCVSS 5.3EG 5.32026-07-30
MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied download_url and download_callback_url values to requests.get without equivalent trusted-host and…
- CVE-2026-64873CRITICALCVSS 9.8EG 9.82026-07-23
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
- CVE-2026-64968MEDIUMCVSS 5.1EG 5.12026-08-20
ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP en…
- CVE-2026-6497MEDIUMCVSS 6.3EG 6.32026-04-17
A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulati…
- CVE-2026-65056HIGHCVSS 8.2EG 8.22026-07-21
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validate…
- CVE-2026-65057CRITICALCVSS 9.3EG 9.32026-07-21
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck …
- CVE-2026-6514HIGHCVSS 7.5EG 7.52026-05-14
The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations…
- CVE-2026-65317HIGHCVSS 8.6EG 8.62026-07-21
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplyi…
- CVE-2026-65318HIGHCVSS 8.6EG 8.62026-07-21
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs…
- CVE-2026-65442HIGHCVSS 7.2EG 7.22026-07-27
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
- CVE-2026-65466MEDIUMCVSS 4.9EG 4.92026-07-23
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
- CVE-2026-65467MEDIUMCVSS 4.9EG 4.92026-07-23
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
- CVE-2026-65496MEDIUMCVSS 4.4EG 4.42026-07-23
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
- CVE-2026-65516HIGHCVSS 7.2EG 7.22026-07-23
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
- CVE-2026-65558MEDIUMCVSS 5.4EG 5.42026-07-27
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
- CVE-2026-65593MEDIUMCVSS 5.4EG 5.42026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing confi…
- CVE-2026-65618MEDIUMCVSS 6.5EG 6.52026-07-27
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
- CVE-2026-6573MEDIUMCVSS 6.3EG 6.32026-04-19
A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server…
- CVE-2026-65801CRITICALCVSS 10.0EG 10.02026-08-20
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-65813HIGHCVSS 8.8EG 8.82026-08-11
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-65818CRITICALCVSS 9.9EG 9.92026-09-03
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
- CVE-2026-65842HIGHCVSS 8.2EG 8.22026-08-20
Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can m…
- CVE-2026-6587MEDIUMCVSS 6.3EG 6.32026-04-20
A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the compone…
- CVE-2026-65923MEDIUMCVSS 6.8EG 6.82026-07-27
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity…
- CVE-2026-65924MEDIUMCVSS 6.5EG 6.52026-07-27
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could ca…
- CVE-2026-65925MEDIUMCVSS 6.5EG 6.52026-07-27
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →