CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,683 vulnerabilities with CWE-918
CVE-2026-33024
CRITICAL
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator
CVSS 9.1
CVE-2026-32949
HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVE-2026-32812
MEDIUM
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
CVSS 6.8
CVE-2026-32828
MEDIUM
Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
CVSS 4.9
CVE-2026-29107
MEDIUM
SuiteCRM vulnerable to authenticated SSRF via PDF export
CVSS 5.0
CVE-2026-29097
HIGH
SuiteCRM Server-Side Request Forgery and Denial of Service via RSS Feed Dashlet
CVSS 7.5
CVE-2026-32037
MEDIUM
OpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment Handling
CVSS 6.0
CVE-2026-32019
HIGH
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
CVE-2026-33321
HIGH
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
CVSS 7.6
CVE-2026-32169
CRITICAL
Azure Cloud Shell Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-26139
HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26138
HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26137
CRITICAL
Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-26120
MEDIUM
Microsoft Bing Tampering Vulnerability
CVSS 6.5
CVE-2026-30404
HIGH
wgcloud 3.6.3 Database Connection Test - Server-Side Request Forgery
CVSS 7.5
CVE-2026-31989
HIGH
OpenClaw < 2026.3.1 - Server-Side Request Forgery via web_search Citation Redirect
CVSS 7.4
CVE-2026-32255
HIGH
Kan is Vulnerable to Unauthenticated SSRF via Attachment Download Endpoint
CVSS 8.6
CVE-2026-4366
MEDIUM
Keycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloak
CVSS 5.8
CVE-2026-22181
HIGH
OpenClaw < 2026.3.2 - DNS Pinning Bypass via Environment Proxy Configuration in web_fetch
CVSS 7.6
CVE-2026-25534
CRITICAL
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
CVSS 9.1
CVE-2026-4308
MEDIUM
frdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forgery
CVSS 6.3
CVE-2026-4284
MEDIUM
taoofagi easegen-admin PPT File PPTUtil.java downloadFile server-side request forgery
CVSS 4.7
CVE-2026-2455
MEDIUM
SSRF bypass via IPv4-mapped IPv6 literals
CVSS 4.3
CVE-2026-4231
HIGH
vanna-ai vanna Endpoint __init__.py run_sql server-side request forgery
CVSS 7.3
CVE-2026-4215
MEDIUM
FlowCI flow-core-x SMTP Host ConfigServiceImpl.java save server-side request forgery
CVSS 6.3
Details
Vulnerabilities
2,683