CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,678 vulnerabilities with CWE-918
CVE-2026-12210 MEDIUM
universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery
CVSS 6.3
CVE-2026-53827 MEDIUM
OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action Forwarding
CVSS 6.5
CVE-2026-47268 MEDIUM
Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host
CVSS 6.4
CVE-2026-46717 HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
CVSS 7.7
CVE-2026-53607 LOW
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
CVSS 3.7
CVE-2026-45012 HIGH
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
CVSS 7.6
CVE-2026-50552 MEDIUM
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
CVSS 6.3
CVE-2026-47260 HIGH
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
CVSS 7.7
CVE-2026-53812 HIGH
OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Interactions
CVSS 7.7
CVE-2026-53782 HIGH
Summarize < 0.17.0 SSRF via podcast:transcript URL fetch
CVSS 7.4
CVE-2026-47170 HIGH
Garlic-Hub < 1.1 - Authenticated Server-Side Request Forgery via uploadFromUrl
CVSS 7.7
CVE-2026-47157 MEDIUM
aiograpi: Unsafe signup challenge path handling
CVSS 6.5
CVE-2026-46698 MEDIUM
Fediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX action
CVSS 5.3
CVE-2026-46697 HIGH
Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endpoint
CVSS 7.5
CVE-2026-44492 HIGH
Axios < 0.32.0 and 1.0.0-1.15.x - NO_PROXY Bypass via IPv4-Mapped IPv6
CVSS 8.6
CVE-2026-3341 MEDIUM
IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services
CVSS 5.4
CVE-2026-48998 MEDIUM
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVSS 5.3
CVE-2026-9204 MEDIUM
Server-Side Request Forgery (SSRF) in GitLab
CVSS 5.3
CVE-2026-40999 HIGH
Spring WS SSRF via unvalidated WS-Addressing reply destinations
CVSS 8.6
CVE-2026-50131 HIGH
Fedify validatePublicUrl - Special-Use IPv4 Server-Side Request Forgery Bypass
CVSS 8.6
CVE-2026-50127 MEDIUM
Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)
CVSS 5.9
CVE-2026-46683 MEDIUM
Snappy: SSRF and local file read via the xsl-style-sheet option
CVE-2026-20252 HIGH
Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise
CVSS 7.6
CVE-2026-48858 MEDIUM
ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
CVSS 6.5
CVE-2026-46497 LOW
SSRF via sitemap-derived URLs in Crawlee for Python
Details
Vulnerabilities 2,678