CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 69 of 73
- CVE-2026-77822CRITICALCVSS 9.6EG 9.62026-09-04
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
- CVE-2026-77866CRITICALCVSS 9.0EG 9.02026-09-15
Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserv…
- CVE-2026-7798MEDIUMCVSS 5.4EG 5.42026-05-22
The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the …
- CVE-2026-78003CRITICALCVSS 9.8EG 9.82026-08-22
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which acc…
- CVE-2026-78061MEDIUMCVSS 6.3EG 6.32026-08-23
A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to s…
- CVE-2026-78205MEDIUMCVSS 5.8EG 5.82026-08-24
BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, CGNAT). In versions 1.4.19 th…
- CVE-2026-78269MEDIUMCVSS 6.4EG 6.42026-08-24
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
- CVE-2026-78277MEDIUMCVSS 4.9EG 4.92026-08-24
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
- CVE-2026-78385HIGHCVSS 8.2EG 8.22026-08-24
RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF rendering. Prior to the fix, WeasyPrint used its def…
- CVE-2026-78495MEDIUMCVSS 5.3EG 5.32026-08-27
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
- CVE-2026-78498MEDIUMCVSS 5.1EG 5.12026-08-27
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
- CVE-2026-78499MEDIUMCVSS 5.1EG 5.12026-08-27
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
- CVE-2026-78500MEDIUMCVSS 5.1EG 5.12026-08-27
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
- CVE-2026-78682HIGHCVSS 7.5EG 7.52026-08-25
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the request…
- CVE-2026-7890MEDIUMCVSS 6.4EG 6.42026-05-21
In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses. The Concrete CMS security team gave this vulnerabili…
- CVE-2026-79425HIGHCVSS 8.1EG 8.12026-09-15
An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.
- CVE-2026-79635HIGHCVSS 7.3EG 7.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially ex…
- CVE-2026-79659HIGHCVSS 7.7EG 7.72026-08-25
Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbitra…
- CVE-2026-79671MEDIUMCVSS 5.5EG 5.52026-08-25
Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-reso…
- CVE-2026-79717MEDIUMCVSS 6.4EG 6.42026-08-25
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, inclu…
- CVE-2026-79723MEDIUMCVSS 5.0EG 5.02026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
- CVE-2026-79747HIGHCVSS 7.1EG 7.12026-08-31
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authenticated non-admin user can register a server…
- CVE-2026-79749HIGHCVSS 7.6EG 7.62026-08-31
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, MCPHub's SSRF guard in src/utils/ssrf.ts uses a custo…
- CVE-2026-79788HIGHCVSS 7.1EG 7.12026-08-25
In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result,…
- CVE-2026-80123HIGHCVSS 7.5EG 7.52026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially ex…
- CVE-2026-80181CRITICALCVSS 9.1EG 9.12026-09-04
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.
- CVE-2026-8034CRITICALCVSS 9.8EG 9.82026-05-07
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the …
- CVE-2026-80347HIGHCVSS 7.5EG 7.52026-08-26
mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, an…
- CVE-2026-80350HIGHCVSS 7.1EG 7.12026-08-26
OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetI…
- CVE-2026-8081MEDIUMCVSS 6.3EG 6.32026-05-07
A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argu…
- CVE-2026-81091HIGHCVSS 8.6EG 8.62026-08-27
The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __m…
- CVE-2026-81093HIGHCVSS 8.6EG 8.62026-08-27
The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from src/utils/generic.ts, which confirmed the…
- CVE-2026-81207HIGHCVSS 8.5EG 8.52026-09-10
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL bod…
- CVE-2026-81213HIGHCVSS 8.6EG 8.62026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
- CVE-2026-81265HIGHCVSS 7.5EG 7.52026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5.
- CVE-2026-81357HIGHCVSS 8.2EG 8.22026-09-08
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-81421HIGHCVSS 7.3EG 7.32026-08-26
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It…
- CVE-2026-81443MEDIUMCVSS 6.4EG 6.42026-09-17
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-sid…
- CVE-2026-81446HIGHCVSS 7.4EG 7.42026-09-17
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-s…
- CVE-2026-81678HIGHCVSS 7.5EG 7.52026-08-27
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can…
- CVE-2026-81806HIGHCVSS 7.2EG 7.22026-09-08
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
- CVE-2026-81848LOWCVSS 3.5EG 3.52026-08-27
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can lead to server-s…
- CVE-2026-81889HIGHCVSS 8.6EG 8.62026-08-31
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because…
- CVE-2026-8193MEDIUMCVSS 6.3EG 6.32026-05-09
A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice PDF Rendering. Executing a manipulation can lead to server-side request forgery. The atta…
- CVE-2026-82081MEDIUMCVSS 6.4EG 6.42026-08-28
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.
- CVE-2026-82097HIGHCVSS 8.8EG 8.82026-09-10
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
- CVE-2026-82234HIGHCVSS 8.2EG 8.22026-08-28
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can us…
- CVE-2026-82241HIGHCVSS 7.1EG 7.12026-08-28
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default bla…
- CVE-2026-82243HIGHCVSS 7.6EG 7.62026-08-28
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak inter…
- CVE-2026-82246HIGHCVSS 7.1EG 7.12026-08-28
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses fr…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →