CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,678 vulnerabilities with CWE-918
CVE-2026-12210
MEDIUM
universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery
CVSS 6.3
CVE-2026-53827
MEDIUM
OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action Forwarding
CVSS 6.5
CVE-2026-47268
MEDIUM
Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host
CVSS 6.4
CVE-2026-46717
HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
CVSS 7.7
CVE-2026-53607
LOW
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
CVSS 3.7
CVE-2026-45012
HIGH
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
CVSS 7.6
CVE-2026-50552
MEDIUM
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
CVSS 6.3
CVE-2026-47260
HIGH
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
CVSS 7.7
CVE-2026-53812
HIGH
OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Interactions
CVSS 7.7
CVE-2026-53782
HIGH
Summarize < 0.17.0 SSRF via podcast:transcript URL fetch
CVSS 7.4
CVE-2026-47170
HIGH
Garlic-Hub < 1.1 - Authenticated Server-Side Request Forgery via uploadFromUrl
CVSS 7.7
CVE-2026-47157
MEDIUM
aiograpi: Unsafe signup challenge path handling
CVSS 6.5
CVE-2026-46698
MEDIUM
Fediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX action
CVSS 5.3
CVE-2026-46697
HIGH
Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endpoint
CVSS 7.5
CVE-2026-44492
HIGH
Axios < 0.32.0 and 1.0.0-1.15.x - NO_PROXY Bypass via IPv4-Mapped IPv6
CVSS 8.6
CVE-2026-3341
MEDIUM
IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services
CVSS 5.4
CVE-2026-48998
MEDIUM
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVSS 5.3
CVE-2026-9204
MEDIUM
Server-Side Request Forgery (SSRF) in GitLab
CVSS 5.3
CVE-2026-40999
HIGH
Spring WS SSRF via unvalidated WS-Addressing reply destinations
CVSS 8.6
CVE-2026-50131
HIGH
Fedify validatePublicUrl - Special-Use IPv4 Server-Side Request Forgery Bypass
CVSS 8.6
CVE-2026-50127
MEDIUM
Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)
CVSS 5.9
CVE-2026-46683
MEDIUM
Snappy: SSRF and local file read via the xsl-style-sheet option
CVE-2026-20252
HIGH
Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise
CVSS 7.6
CVE-2026-48858
MEDIUM
ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
CVSS 6.5
CVE-2026-46497
LOW
SSRF via sitemap-derived URLs in Crawlee for Python
Details
Vulnerabilities
2,678