CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,437 vulnerabilities with CWE-918
CVE-2026-6979 MEDIUM
devlikeapro WAHA API Request media.controller.ts server-side request forgery
CVSS 6.3
CVE-2026-41488 LOW
angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
CVSS 3.1
CVE-2026-41481 MEDIUM
LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
CVSS 6.5
CVE-2026-42043 HIGH
Axios <1.15.1, <0.31.1 - Auth Bypass
CVSS 7.2
CVE-2026-42038 MEDIUM
Axios <1.15.1, <0.31.1 - Proxy Bypass
CVSS 6.8
CVE-2026-41321 LOW
@astrojs/cloudflare: SSRF via redirect following in Cloudflare image-binding-transform endpoint
CVSS 2.2
CVE-2026-41323 HIGH
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
CVSS 8.1
CVE-2026-31955 MEDIUM
Xibo CMS has Authenticated Server-Side Request Forgery (SSRF) in Remote DataSet Functionality
CVSS 4.9
CVE-2026-41361 HIGH
OpenClaw < 2026.3.28 - SSRF Guard Bypass via IPv6 Special-Use Ranges
CVSS 7.1
CVE-2026-35431 CRITICAL
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
CVSS 10.0
CVE-2026-32210 CRITICAL
Microsoft Dynamics 365 (online) Spoofing Vulnerability
CVSS 9.3
CVE-2026-26150 HIGH
Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-41272 HIGH
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
CVSS 7.1
CVE-2026-41271 HIGH
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
CVSS 7.1
CVE-2026-41270 HIGH
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVSS 7.1
CVE-2026-41461 HIGH
SocialEngine <= 7.8.0 Blind SSRF via /core/link/preview
CVSS 8.5
CVE-2026-41455 HIGH
WeKan < 8.35 SSRF via Webhook URL
CVSS 8.5
CVE-2026-41177 MEDIUM
Squidex has Blind SSRF via file:// Protocol in Restore API leading to Local File Interaction
CVSS 5.5
CVE-2026-41172 HIGH
Squidex vulnerable to Server-Side Request Forgery (SSRF) via URL-based asset upload (/api/apps/{app}/assets)
CVE-2026-41171 HIGH
SSRF via Jint Scripting Engine HTTP Functions Due to Missing SSRF Protection on "Jint" HttpClient
CVE-2026-41170 HIGH
Squidex has SSRF via Backup Restore Endpoint — Admin-Controlled URL Download Allows Internal and External Requests
CVE-2026-35548 HIGH
guardsix ODBC Enrichment Plugins <5.2.1 - Auth Bypass
CVSS 8.5
CVE-2026-41130 MEDIUM
Craft CMS has a host header injection leading to SSRF via resource-js endpoint
CVE-2026-41129 MEDIUM
Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations
CVE-2026-5921 HIGH
Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack
CVSS 8.9
Details
Vulnerabilities 2,437