CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,437 vulnerabilities with CWE-918
CVE-2026-42404 MEDIUM
Apache Neethi: Unrestricted HTTP Redirect Following in Policy References
CVSS 6.5
CVE-2026-3340 MEDIUM
Server-Side Request Forgery (SSRF) in Langflow URL Component
CVSS 6.5
CVE-2026-7417 HIGH
Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery
CVSS 7.3
CVE-2026-42641 MEDIUM
WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerability
CVSS 5.4
CVE-2026-23773 MEDIUM
Dell Disk Library For Mainframe DLm8700 < 7.0.1.0 or later - SSRF
CVSS 4.3
CVE-2026-7305 MEDIUM
Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery
CVSS 6.3
CVE-2026-7291 MEDIUM
o2oa URL Fetching FileAction.java FileAction server-side request forgery
CVSS 6.3
CVE-2026-42430 MEDIUM
OpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect Handling
CVSS 6.5
CVE-2026-41914 HIGH
OpenClaw < 2026.4.8 - Server-Side Request Forgery in QQ Bot Media Fetch Paths
CVSS 8.5
CVE-2026-41912 HIGH
OpenClaw < 2026.4.8 - Server-Side Request Forgery Policy Bypass via Interaction-Triggered Navigation
CVSS 7.6
CVE-2026-24231 MEDIUM
Nvidia NemoClaw - Information Disclosure
CVSS 6.3
CVE-2026-7223 HIGH
BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery
CVSS 7.3
CVE-2026-7221 HIGH
TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery
CVSS 7.3
CVE-2026-7178 HIGH
ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery
CVSS 7.3
CVE-2026-7177 HIGH
ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery
CVSS 7.3
CVE-2026-7158 HIGH
dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery
CVSS 7.3
CVE-2026-7150 MEDIUM
dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery
CVSS 6.3
CVE-2026-7147 HIGH
JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery
CVSS 7.3
CVE-2026-7146 HIGH
AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery
CVSS 7.3
CVE-2026-7094 HIGH
ShadowCloneLabs GlutamateMCPServers puppeteer_navigate index.ts server-side request forgery
CVSS 7.3
CVE-2026-7084 MEDIUM
HBAI-Ltd Toonflow-app getCodeByLink Endpoint getCodeByLink.ts fetch server-side request forgery
CVSS 6.3
CVE-2026-7065 HIGH
BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request forgery
CVSS 7.3
CVE-2026-7025 HIGH
Typecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery
CVSS 7.3
CVE-2026-6983 MEDIUM
pagekit download server-side request forgery
CVSS 4.7
CVE-2026-6981 MEDIUM
IhateCreatingUserNames2 AiraHub2 Endpoint AiraHub.py sync_agents server-side request forgery
CVSS 6.3
Details
Vulnerabilities 2,437