CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
2,795 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 55 of 56
- CVE-2026-62234HIGHCVSS 8.1EG 8.12026-07-17
Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to re…
- CVE-2026-62240HIGHCVSS 7.4EG 7.42026-07-13
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the securit…
- CVE-2026-62242HIGHCVSS 8.6EG 8.62026-07-13
Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation again…
- CVE-2026-6229HIGHCVSS 7.2EG 7.22026-05-02
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which …
- CVE-2026-62418HIGHCVSS 8.1EG 8.12026-07-20
Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.…
- CVE-2026-62643CRITICALCVSS 10.0EG 10.02026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. N…
- CVE-2026-63086HIGHCVSS 8.6EG 8.62026-07-16
text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issui…
- CVE-2026-63088HIGHCVSS 8.6EG 8.62026-07-16
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_bla…
- CVE-2026-63096MEDIUMCVSS 5.8EG 5.82026-07-17
Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName par…
- CVE-2026-63107HIGHCVSS 7.7EG 7.72026-07-20
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipula…
- CVE-2026-63306HIGHCVSS 8.6EG 8.62026-07-16
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enum…
- CVE-2026-63313HIGHCVSS 7.7EG 7.72026-07-23
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina…
- CVE-2026-6333LOWCVSS 3.5EG 3.52026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-…
- CVE-2026-63730MEDIUMCVSS 5.0EG 5.02026-07-20
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the …
- CVE-2026-63731HIGHCVSS 7.7EG 7.72026-07-20
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse pro…
- CVE-2026-63736MEDIUMCVSS 4.1EG 4.12026-07-20
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role attacker can point an acc…
- CVE-2026-63743MEDIUMCVSS 6.4EG 6.42026-07-20
SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a deni…
- CVE-2026-63744MEDIUMCVSS 4.1EG 4.12026-07-20
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS…
- CVE-2026-63764CRITICALCVSS 8.6EG 9.32026-07-21
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original URL…
- CVE-2026-63769HIGHCVSS 7.7EG 7.72026-07-20
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe intern…
- CVE-2026-6394MEDIUMCVSS 5.4EG 5.42026-05-20
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepti…
- CVE-2026-64626MEDIUMCVSS 6.4EG 6.42026-07-20
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated att…
- CVE-2026-64799UnratedEG 0.02026-07-23
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save re…
- CVE-2026-64873CRITICALCVSS 9.8EG 9.82026-07-23
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
- CVE-2026-6497MEDIUMCVSS 6.3EG 6.32026-04-17
A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulati…
- CVE-2026-65056HIGHCVSS 8.2EG 8.22026-07-21
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validate…
- CVE-2026-65057CRITICALCVSS 9.3EG 9.32026-07-21
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck …
- CVE-2026-6514HIGHCVSS 7.5EG 7.52026-05-14
The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations…
- CVE-2026-65317HIGHCVSS 8.6EG 8.62026-07-21
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplyi…
- CVE-2026-65318HIGHCVSS 8.6EG 8.62026-07-21
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs…
- CVE-2026-65466MEDIUMCVSS 4.9EG 4.92026-07-23
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
- CVE-2026-65467MEDIUMCVSS 4.9EG 4.92026-07-23
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
- CVE-2026-65496MEDIUMCVSS 4.4EG 4.42026-07-23
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
- CVE-2026-65516HIGHCVSS 7.2EG 7.22026-07-23
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
- CVE-2026-65593MEDIUMCVSS 6.3EG 6.32026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing confi…
- CVE-2026-6573MEDIUMCVSS 6.3EG 6.32026-04-19
A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server…
- CVE-2026-6587MEDIUMCVSS 6.3EG 6.32026-04-20
A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the compone…
- CVE-2026-6604HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py of the component Cl…
- CVE-2026-6605HIGHCVSS 7.3EG 7.32026-04-20
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results …
- CVE-2026-6606HIGHCVSS 7.3EG 7.32026-04-20
A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to se…
- CVE-2026-6616MEDIUMCVSS 6.3EG 6.32026-04-20
A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/helper/webpage_extractor.py of the component WebScrap…
- CVE-2026-6617MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Perf…
- CVE-2026-6618MEDIUMCVSS 6.3EG 6.32026-04-20
A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation o…
- CVE-2026-6625HIGHCVSS 7.3EG 7.32026-04-20
A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/i…
- CVE-2026-6649MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can …
- CVE-2026-6744MEDIUMCVSS 6.3EG 6.32026-04-21
A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been…
- CVE-2026-6812MEDIUMCVSS 4.4EG 4.42026-05-02
The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via the ona_activate_child_theme. This makes it possible for authenticated attackers, with administrator-level access and a…
- CVE-2026-6979MEDIUMCVSS 6.3EG 6.32026-04-25
A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery. The attack can b…
- CVE-2026-6981MEDIUMCVSS 6.3EG 6.32026-04-25
A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manip…
- CVE-2026-6983MEDIUMCVSS 4.7EG 4.72026-04-25
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Re…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →