CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 65 of 73
- CVE-2026-65941HIGHCVSS 8.8EG 8.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
- CVE-2026-65985MEDIUMCVSS 6.0EG 6.02026-08-18
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.addr…
- CVE-2026-6604HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py of the component Cl…
- CVE-2026-6605HIGHCVSS 7.3EG 7.32026-04-20
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results …
- CVE-2026-6606HIGHCVSS 7.3EG 7.32026-04-20
A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to se…
- CVE-2026-6616MEDIUMCVSS 6.3EG 6.32026-04-20
A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/helper/webpage_extractor.py of the component WebScrap…
- CVE-2026-6617MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Perf…
- CVE-2026-6618MEDIUMCVSS 6.3EG 6.32026-04-20
A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation o…
- CVE-2026-6625HIGHCVSS 7.3EG 7.32026-04-20
A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/i…
- CVE-2026-66304HIGHCVSS 7.5EG 7.52026-09-08
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
- CVE-2026-66325MEDIUMCVSS 6.1EG 6.12026-08-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-66415HIGHCVSS 8.5EG 8.52026-07-30
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Bluepr…
- CVE-2026-66437MEDIUMCVSS 4.9EG 4.92026-07-27
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
- CVE-2026-6649MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can …
- CVE-2026-66608MEDIUMCVSS 6.4EG 6.42026-09-17
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
- CVE-2026-66654MEDIUMCVSS 6.0EG 6.02026-08-13
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
- CVE-2026-66704HIGHCVSS 7.2EG 7.22026-08-13
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
- CVE-2026-66794CRITICALCVSS 9.3EG 9.32026-08-19
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. …
- CVE-2026-66800HIGHCVSS 7.5EG 8.62026-08-20
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
- CVE-2026-66842HIGHCVSS 8.8EG 8.82026-09-02
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an …
- CVE-2026-66901HIGHCVSS 7.5EG 7.52026-08-04
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hos…
- CVE-2026-67101CRITICALCVSS 9.3EG 9.32026-09-18
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not ac…
- CVE-2026-67173MEDIUMCVSS 5.1EG 5.12026-07-28
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph data could set an image path to a malicious URI. When a victi…
- CVE-2026-67311MEDIUMCVSS 6.8EG 6.82026-08-01
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource poin…
- CVE-2026-67346HIGHCVSS 8.6EG 8.62026-07-30
Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers…
- CVE-2026-67424HIGHCVSS 8.5EG 8.52026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and src/cor…
- CVE-2026-67426CRITICALCVSS 9.3EG 9.32026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supp…
- CVE-2026-67428HIGHCVSS 8.5EG 8.52026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graph…
- CVE-2026-67435MEDIUMCVSS 6.0EG 6.02026-07-29
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirects while forwarding caller-supplied credential headers other …
- CVE-2026-67436HIGHCVSS 8.3EG 8.32026-07-29
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with respon…
- CVE-2026-6744MEDIUMCVSS 6.3EG 6.32026-04-21
A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been…
- CVE-2026-67530MEDIUMCVSS 6.4EG 6.42026-07-30
WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its validation in src/lib/automations/validate.ts allowed an authenticated user with automati…
- CVE-2026-67620HIGHCVSS 7.7EG 7.72026-08-08
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cl…
- CVE-2026-6812MEDIUMCVSS 4.4EG 4.42026-05-02
The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via the ona_activate_child_theme. This makes it possible for authenticated attackers, with administrator-level access and a…
- CVE-2026-68536CRITICALCVSS 9.8EG 9.82026-09-16
Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
- CVE-2026-68558HIGHCVSS 8.5EG 8.52026-08-19
Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-1…
- CVE-2026-68927LOWCVSS 3.0EG 3.02026-08-18
MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before appe…
- CVE-2026-69078HIGHCVSS 8.8EG 8.82026-08-03
CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdow…
- CVE-2026-69192HIGHCVSS 7.7EG 7.72026-08-03
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and …
- CVE-2026-69198MEDIUMCVSS 6.9EG 6.92026-08-03
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own …
- CVE-2026-69223CRITICALCVSS 9.1EG 9.12026-08-11
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
- CVE-2026-69246HIGHCVSS 7.2EG 7.22026-08-03
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Hos…
- CVE-2026-69257HIGHCVSS 8.6EG 8.62026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.25…
- CVE-2026-69361MEDIUMCVSS 6.5EG 6.52026-09-08
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-69502CRITICALCVSS 10.0EG 10.02026-08-21
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-69543HIGHCVSS 8.5EG 8.52026-08-20
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69683HIGHCVSS 7.7EG 7.72026-09-08
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- CVE-2026-6979MEDIUMCVSS 6.3EG 6.32026-04-25
A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery. The attack can b…
- CVE-2026-6981MEDIUMCVSS 6.3EG 6.32026-04-25
A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manip…
- CVE-2026-6983MEDIUMCVSS 4.7EG 4.72026-04-25
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Re…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →