CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 70 of 73
- CVE-2026-82262MEDIUMCVSS 6.8EG 6.82026-08-28
Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server is…
- CVE-2026-82263MEDIUMCVSS 6.8EG 6.82026-08-28
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitra…
- CVE-2026-82268HIGHCVSS 7.5EG 7.52026-08-28
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gr…
- CVE-2026-82270HIGHCVSS 7.5EG 7.52026-08-28
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward re…
- CVE-2026-82285HIGHCVSS 8.2EG 8.22026-08-28
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attac…
- CVE-2026-82289HIGHCVSS 7.4EG 7.42026-08-28
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled hostna…
- CVE-2026-82476MEDIUMCVSS 5.3EG 5.32026-08-29
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal host…
- CVE-2026-82477MEDIUMCVSS 5.8EG 5.82026-08-29
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
- CVE-2026-82556MEDIUMCVSS 6.3EG 6.32026-08-30
A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation result…
- CVE-2026-82630HIGHCVSS 7.3EG 7.32026-08-31
A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/TestController…
- CVE-2026-82638HIGHCVSS 7.5EG 7.52026-08-30
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses …
- CVE-2026-82667MEDIUMCVSS 4.7EG 4.72026-08-31
A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of the argument endpo…
- CVE-2026-82757MEDIUMCVSS 6.3EG 6.32026-09-07
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 …
- CVE-2026-82801HIGHCVSS 7.3EG 7.32026-08-31
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in s…
- CVE-2026-82802MEDIUMCVSS 5.3EG 5.32026-08-31
A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipu…
- CVE-2026-82852MEDIUMCVSS 5.4EG 5.42026-08-31
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
- CVE-2026-82866MEDIUMCVSS 6.8EG 6.82026-08-31
@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template f…
- CVE-2026-82905MEDIUMCVSS 6.3EG 6.32026-08-31
A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side …
- CVE-2026-82957HIGHCVSS 7.3EG 7.32026-08-31
A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of…
- CVE-2026-8320MEDIUMCVSS 4.7EG 4.72026-05-11
A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of the component updatePlatformConfigByKey …
- CVE-2026-8328MEDIUMCVSS 5.9EG 5.92026-05-13
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse22…
- CVE-2026-83543MEDIUMCVSS 4.1EG 4.12026-09-05
The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the r…
- CVE-2026-83548CRITICALCVSS 10.0EG 10.0⚠ KEV2026-09-01
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized ac…
- CVE-2026-83744MEDIUMCVSS 4.3EG 4.32026-09-01
A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation…
- CVE-2026-84175MEDIUMCVSS 5.3EG 5.32026-09-02
In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows H…
- CVE-2026-84196HIGHCVSS 7.7EG 7.72026-09-01
Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers c…
- CVE-2026-84199HIGHCVSS 7.7EG 7.72026-09-01
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions ca…
- CVE-2026-84207MEDIUMCVSS 5.4EG 5.42026-09-01
Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach i…
- CVE-2026-84377MEDIUMCVSS 6.5EG 6.52026-09-02
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and…
- CVE-2026-84697MEDIUMCVSS 5.3EG 5.32026-09-02
Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply host…
- CVE-2026-84761HIGHCVSS 7.2EG 7.22026-09-03
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
- CVE-2026-84772MEDIUMCVSS 5.5EG 5.52026-09-02
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
- CVE-2026-85106MEDIUMCVSS 6.3EG 6.32026-09-03
A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url lead…
- CVE-2026-85163MEDIUMCVSS 6.5EG 6.52026-09-03
AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter …
- CVE-2026-85164HIGHCVSS 7.1EG 7.12026-09-03
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can s…
- CVE-2026-85172MEDIUMCVSS 6.4EG 6.42026-09-03
n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP…
- CVE-2026-85179HIGHCVSS 8.5EG 8.52026-09-03
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private n…
- CVE-2026-85180HIGHCVSS 7.5EG 7.52026-09-03
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest,…
- CVE-2026-85242MEDIUMCVSS 6.9EG 6.92026-09-03
PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, l…
- CVE-2026-85305MEDIUMCVSS 5.4EG 5.42026-09-03
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
- CVE-2026-85380HIGHCVSS 7.3EG 7.32026-09-04
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the comp…
- CVE-2026-85528MEDIUMCVSS 5.3EG 5.32026-09-04
Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker ab…
- CVE-2026-85608HIGHCVSS 7.5EG 7.52026-09-04
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query …
- CVE-2026-85609HIGHCVSS 7.5EG 7.52026-09-04
Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url q…
- CVE-2026-85612HIGHCVSS 7.5EG 7.52026-09-04
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the A…
- CVE-2026-85614HIGHCVSS 8.6EG 8.62026-09-04
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protect…
- CVE-2026-85650MEDIUMCVSS 5.4EG 5.42026-09-04
Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert …
- CVE-2026-85662MEDIUMCVSS 5.3EG 5.32026-09-04
Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit do…
- CVE-2026-85666HIGHCVSS 7.5EG 7.52026-09-04
OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along wi…
- CVE-2026-85673HIGHCVSS 7.5EG 7.52026-09-04
LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but …
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →