CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,681 vulnerabilities with CWE-918
CVE-2026-34443
MEDIUM
FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()
CVSS 5.3
CVE-2026-34740
MEDIUM
AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation
CVSS 6.5
CVE-2026-34367
HIGH
InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field
CVSS 7.6
CVE-2026-34366
HIGH
InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field
CVSS 7.6
CVE-2026-34365
HIGH
InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field
CVSS 7.6
CVE-2026-33185
MEDIUM
Discourse: Group SMTP test endpoint susceptible to SSRF
CVSS 5.0
CVE-2026-5205
MEDIUM
chatwoot Webhook API trigger.rb Trigger server-side request forgery
CVSS 6.3
CVE-2026-34360
MEDIUM
HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
CVSS 5.8
CVE-2026-34504
HIGH
OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider
CVSS 8.3
CVE-2026-34163
HIGH
Server-Side Request Forgery via MCP Tools Endpoint in FastGPT
CVSS 7.7
CVE-2026-34162
CRITICAL
FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft
CVSS 10.0
CVE-2026-3881
MEDIUM
Performance Monitor WordPress Plugin <=1.0.6 - Unauthenticated Blind Server-Side Request Forgery
CVSS 5.8
CVE-2026-34881
MEDIUM
OpenStack Glance <29.1.1, 30.x<30.1.1, 31.0.0 SSRF via Image Import URL Redirect
CVSS 5.0
CVE-2026-4789
CRITICAL
Kyverno >=1.16.0 - CEL HTTP Function Server-Side Request Forgery
CVSS 9.8
CVE-2026-27018
HIGH
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
CVSS 7.5
CVE-2026-31804
MEDIUM
Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through the Plex Media Server
CVSS 4.0
CVE-2026-29925
HIGH
Invoice Ninja 5.12.46 and 5.12.48 - CheckDatabaseRequest Server-Side Request Forgery
CVSS 7.7
CVE-2026-5126
MEDIUM
SourceCodester RSS Feed Parser file_get_contents server-side request forgery
CVSS 6.3
CVE-2026-29954
HIGH
KubePlus 4.1.4 - chartURL Server-Side Request Forgery and Header Injection
CVSS 7.6
CVE-2026-2286
CRITICAL
CrewAI 1.0 - SSRF in RAG Search Tools
CVSS 9.8
CVE-2026-0560
HIGH
Server-Side Request Forgery (SSRF) in parisneo/lollms
CVSS 7.5
CVE-2026-5016
HIGH
elecV2 elecV2P URL mock eAxios server-side request forgery
CVSS 7.3
CVE-2026-33992
MEDIUM
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
CVSS 6.5
CVE-2026-33953
HIGH
LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce
CVSS 8.5
CVE-2026-31945
HIGH
LibreChat Server-Side Request Forgery using DNS resolution
CVSS 7.7
Details
Vulnerabilities
2,681