CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,437 vulnerabilities with CWE-918
CVE-2026-42404
MEDIUM
Apache Neethi: Unrestricted HTTP Redirect Following in Policy References
CVSS 6.5
CVE-2026-3340
MEDIUM
Server-Side Request Forgery (SSRF) in Langflow URL Component
CVSS 6.5
CVE-2026-7417
HIGH
Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery
CVSS 7.3
CVE-2026-42641
MEDIUM
WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerability
CVSS 5.4
CVE-2026-23773
MEDIUM
Dell Disk Library For Mainframe DLm8700 < 7.0.1.0 or later - SSRF
CVSS 4.3
CVE-2026-7305
MEDIUM
Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery
CVSS 6.3
CVE-2026-7291
MEDIUM
o2oa URL Fetching FileAction.java FileAction server-side request forgery
CVSS 6.3
CVE-2026-42430
MEDIUM
OpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect Handling
CVSS 6.5
CVE-2026-41914
HIGH
OpenClaw < 2026.4.8 - Server-Side Request Forgery in QQ Bot Media Fetch Paths
CVSS 8.5
CVE-2026-41912
HIGH
OpenClaw < 2026.4.8 - Server-Side Request Forgery Policy Bypass via Interaction-Triggered Navigation
CVSS 7.6
CVE-2026-24231
MEDIUM
Nvidia NemoClaw - Information Disclosure
CVSS 6.3
CVE-2026-7223
HIGH
BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery
CVSS 7.3
CVE-2026-7221
HIGH
TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery
CVSS 7.3
CVE-2026-7178
HIGH
ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery
CVSS 7.3
CVE-2026-7177
HIGH
ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery
CVSS 7.3
CVE-2026-7158
HIGH
dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery
CVSS 7.3
CVE-2026-7150
MEDIUM
dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery
CVSS 6.3
CVE-2026-7147
HIGH
JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery
CVSS 7.3
CVE-2026-7146
HIGH
AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery
CVSS 7.3
CVE-2026-7094
HIGH
ShadowCloneLabs GlutamateMCPServers puppeteer_navigate index.ts server-side request forgery
CVSS 7.3
CVE-2026-7084
MEDIUM
HBAI-Ltd Toonflow-app getCodeByLink Endpoint getCodeByLink.ts fetch server-side request forgery
CVSS 6.3
CVE-2026-7065
HIGH
BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request forgery
CVSS 7.3
CVE-2026-7025
HIGH
Typecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery
CVSS 7.3
CVE-2026-6983
MEDIUM
pagekit download server-side request forgery
CVSS 4.7
CVE-2026-6981
MEDIUM
IhateCreatingUserNames2 AiraHub2 Endpoint AiraHub.py sync_agents server-side request forgery
CVSS 6.3
Details
Vulnerabilities
2,437