CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,681 vulnerabilities with CWE-918
CVE-2026-34443 MEDIUM
FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()
CVSS 5.3
CVE-2026-34740 MEDIUM
AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation
CVSS 6.5
CVE-2026-34367 HIGH
InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field
CVSS 7.6
CVE-2026-34366 HIGH
InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field
CVSS 7.6
CVE-2026-34365 HIGH
InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field
CVSS 7.6
CVE-2026-33185 MEDIUM
Discourse: Group SMTP test endpoint susceptible to SSRF
CVSS 5.0
CVE-2026-5205 MEDIUM
chatwoot Webhook API trigger.rb Trigger server-side request forgery
CVSS 6.3
CVE-2026-34360 MEDIUM
HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
CVSS 5.8
CVE-2026-34504 HIGH
OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider
CVSS 8.3
CVE-2026-34163 HIGH
Server-Side Request Forgery via MCP Tools Endpoint in FastGPT
CVSS 7.7
CVE-2026-34162 CRITICAL
FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft
CVSS 10.0
CVE-2026-3881 MEDIUM
Performance Monitor WordPress Plugin <=1.0.6 - Unauthenticated Blind Server-Side Request Forgery
CVSS 5.8
CVE-2026-34881 MEDIUM
OpenStack Glance <29.1.1, 30.x<30.1.1, 31.0.0 SSRF via Image Import URL Redirect
CVSS 5.0
CVE-2026-4789 CRITICAL
Kyverno >=1.16.0 - CEL HTTP Function Server-Side Request Forgery
CVSS 9.8
CVE-2026-27018 HIGH
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
CVSS 7.5
CVE-2026-31804 MEDIUM
Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through the Plex Media Server
CVSS 4.0
CVE-2026-29925 HIGH
Invoice Ninja 5.12.46 and 5.12.48 - CheckDatabaseRequest Server-Side Request Forgery
CVSS 7.7
CVE-2026-5126 MEDIUM
SourceCodester RSS Feed Parser file_get_contents server-side request forgery
CVSS 6.3
CVE-2026-29954 HIGH
KubePlus 4.1.4 - chartURL Server-Side Request Forgery and Header Injection
CVSS 7.6
CVE-2026-2286 CRITICAL
CrewAI 1.0 - SSRF in RAG Search Tools
CVSS 9.8
CVE-2026-0560 HIGH
Server-Side Request Forgery (SSRF) in parisneo/lollms
CVSS 7.5
CVE-2026-5016 HIGH
elecV2 elecV2P URL mock eAxios server-side request forgery
CVSS 7.3
CVE-2026-33992 MEDIUM
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
CVSS 6.5
CVE-2026-33953 HIGH
LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce
CVSS 8.5
CVE-2026-31945 HIGH
LibreChat Server-Side Request Forgery using DNS resolution
CVSS 7.7
Details
Vulnerabilities 2,681