CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
2,795 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 54 of 56
- CVE-2026-5737MEDIUMCVSS 6.5EG 6.52026-05-28
The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled refer…
- CVE-2026-57372HIGHCVSS 7.2EG 7.22026-07-13
Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.
- CVE-2026-57407HIGHCVSS 7.2EG 7.22026-07-13
Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.
- CVE-2026-57413MEDIUMCVSS 6.4EG 6.42026-07-13
Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.
- CVE-2026-57573HIGHCVSS 8.6EG 8.62026-07-06
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed se…
- CVE-2026-57575MEDIUMCVSS 6.9EG 6.92026-07-10
Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions befor…
- CVE-2026-57627MEDIUMCVSS 4.9EG 4.92026-06-26
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
- CVE-2026-57681MEDIUMCVSS 6.4EG 6.42026-07-02
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
- CVE-2026-5773HIGHCVSS 7.5EG 7.52026-05-13
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection …
- CVE-2026-57940LOWCVSS 2.1EG 2.12026-06-26
HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any vali…
- CVE-2026-57947HIGHCVSS 8.5EG 8.52026-06-29
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshol…
- CVE-2026-57987MEDIUMCVSS 6.5EG 6.52026-07-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-57993HIGHCVSS 7.4EG 7.42026-07-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-5803MEDIUMCVSS 6.3EG 6.32026-04-08
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulati…
- CVE-2026-58278MEDIUMCVSS 5.4EG 5.42026-07-03
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-5832HIGHCVSS 7.3EG 7.32026-04-09
A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation …
- CVE-2026-58404MEDIUMCVSS 6.8EG 6.82026-07-06
Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alte…
- CVE-2026-58418MEDIUMCVSS 6.5EG 6.52026-07-03
SSRF via HTTP Redirect in Repository Migration
- CVE-2026-58468MEDIUMCVSS 5.5EG 5.52026-07-07
NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request no…
- CVE-2026-58478MEDIUMCVSS 6.5EG 6.52026-07-14
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callba…
- CVE-2026-58501MEDIUMCVSS 5.9EG 5.92026-07-08
Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to …
- CVE-2026-59095HIGHCVSS 7.7EG 7.72026-07-02
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (im…
- CVE-2026-59101MEDIUMCVSS 5.8EG 5.82026-07-02
AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attac…
- CVE-2026-5921HIGHCVSS 8.9EG 8.92026-04-21
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook r…
- CVE-2026-59221HIGHCVSS 7.7EG 7.72026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths only eight times, allowing a nine-times per…
- CVE-2026-5936CRITICALCVSS 9.8EG 9.82026-04-13
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachab…
- CVE-2026-59702CRITICALCVSS 9.3EG 9.32026-07-08
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// U…
- CVE-2026-59707HIGHCVSS 8.6EG 8.62026-07-07
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to gallery…
- CVE-2026-59806HIGHCVSS 7.4EG 7.42026-07-08
Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch()…
- CVE-2026-59867HIGHCVSS 7.1EG 7.12026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-contro…
- CVE-2026-60033MEDIUMCVSS 5.1EG 5.12026-07-20
Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.
- CVE-2026-60091HIGHCVSS 7.2EG 7.22026-07-10
PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attack…
- CVE-2026-60105HIGHCVSS 8.6EG 8.62026-07-08
Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4…
- CVE-2026-6011MEDIUMCVSS 5.6EG 5.62026-04-10
A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to …
- CVE-2026-6111MEDIUMCVSS 6.3EG 6.32026-04-12
A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery…
- CVE-2026-6119MEDIUMCVSS 6.3EG 6.32026-04-12
A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request forgery. The attack may be performed from …
- CVE-2026-61429HIGHCVSS 8.5EG 8.52026-07-11
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs …
- CVE-2026-61430HIGHCVSS 8.5EG 8.52026-07-15
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass…
- CVE-2026-61520HIGHCVSS 7.7EG 7.72026-07-14
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding at…
- CVE-2026-61646MEDIUMCVSS 6.3EG 6.32026-07-15
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to axios, and axios follows redirects by default. An authenticated w…
- CVE-2026-61835HIGHCVSS 7.7EG 7.72026-07-15
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because api/src/request/is-denied-ip…
- CVE-2026-61970MEDIUMCVSS 4.9EG 4.92026-07-13
Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <…
- CVE-2026-62143HIGHCVSS 8.3EG 8.32026-07-13
A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. How…
- CVE-2026-6215MEDIUMCVSS 6.3EG 6.32026-04-13
A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side request forgery. Th…
- CVE-2026-62197HIGHCVSS 8.5EG 8.52026-07-13
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy…
- CVE-2026-6220MEDIUMCVSS 4.7EG 4.72026-04-13
A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServer of the file ServerService.java of the component Video File Download URL Handler. Such manipulation of the argument st…
- CVE-2026-62201HIGHCVSS 7.7EG 7.72026-07-17
OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests …
- CVE-2026-62216MEDIUMCVSS 5.0EG 5.02026-07-17
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenCl…
- CVE-2026-62226HIGHCVSS 8.5EG 8.52026-07-17
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform acti…
- CVE-2026-62227HIGHCVSS 7.7EG 7.72026-07-17
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to r…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →