CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
3,003 vulnerabilities with CWE-918
CVE-2026-14540
HIGH
Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox
CVE-2026-67530
MEDIUM
WACRM: SSRF via the automation `send_webhook` action
CVSS 6.4
CVE-2026-66415
HIGH
Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import()
CVSS 8.5
CVE-2026-64870
MEDIUM
MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation
CVE-2026-57862
HIGH
Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation
CVSS 8.5
CVE-2026-67346
HIGH
Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass
CVSS 8.6
CVE-2026-54885
MEDIUM
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching
CVE-2026-18382
MEDIUM
Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_url
CVSS 6.8
CVE-2026-18381
HIGH
Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address
CVSS 7.6
CVE-2026-18378
HIGH
Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy)
CVSS 7.6
CVE-2026-18369
MEDIUM
Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects
CVSS 5.8
CVE-2026-18353
HIGH
Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass
CVE-2026-54249
MEDIUM
VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection
CVSS 6.8
CVE-2026-46678
MEDIUM
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
CVSS 6.8
CVE-2026-67436
HIGH
Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVE-2026-67435
MEDIUM
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
CVE-2026-67428
HIGH
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
CVSS 8.5
CVE-2026-67426
CRITICAL
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
CVSS 9.3
CVE-2026-67424
HIGH
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
CVSS 8.5
CVE-2026-16328
HIGH
consul-mcp-server vulnerable to server side request forgery leading to token exposure
CVSS 8.6
CVE-2026-54735
CRITICAL
prebid-server's request forgery vulnerability allows for possible host environment data extraction
CVSS 10.0
CVE-2026-54663
MEDIUM
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVSS 6.1
CVE-2026-54660
HIGH
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVSS 7.4
CVE-2026-6089
MEDIUM
WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery
CVSS 4.9
CVE-2026-58189
HIGH
Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification
CVSS 7.5
Details
Vulnerabilities
3,003