CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,683 vulnerabilities with CWE-918
CVE-2026-33024 CRITICAL
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator
CVSS 9.1
CVE-2026-32949 HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVE-2026-32812 MEDIUM
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
CVSS 6.8
CVE-2026-32828 MEDIUM
Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
CVSS 4.9
CVE-2026-29107 MEDIUM
SuiteCRM vulnerable to authenticated SSRF via PDF export
CVSS 5.0
CVE-2026-29097 HIGH
SuiteCRM Server-Side Request Forgery and Denial of Service via RSS Feed Dashlet
CVSS 7.5
CVE-2026-32037 MEDIUM
OpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment Handling
CVSS 6.0
CVE-2026-32019 HIGH
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
CVE-2026-33321 HIGH
OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)
CVSS 7.6
CVE-2026-32169 CRITICAL
Azure Cloud Shell Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-26139 HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26138 HIGH
Microsoft Purview Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-26137 CRITICAL
Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-26120 MEDIUM
Microsoft Bing Tampering Vulnerability
CVSS 6.5
CVE-2026-30404 HIGH
wgcloud 3.6.3 Database Connection Test - Server-Side Request Forgery
CVSS 7.5
CVE-2026-31989 HIGH
OpenClaw < 2026.3.1 - Server-Side Request Forgery via web_search Citation Redirect
CVSS 7.4
CVE-2026-32255 HIGH
Kan is Vulnerable to Unauthenticated SSRF via Attachment Download Endpoint
CVSS 8.6
CVE-2026-4366 MEDIUM
Keycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloak
CVSS 5.8
CVE-2026-22181 HIGH
OpenClaw < 2026.3.2 - DNS Pinning Bypass via Environment Proxy Configuration in web_fetch
CVSS 7.6
CVE-2026-25534 CRITICAL
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
CVSS 9.1
CVE-2026-4308 MEDIUM
frdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forgery
CVSS 6.3
CVE-2026-4284 MEDIUM
taoofagi easegen-admin PPT File PPTUtil.java downloadFile server-side request forgery
CVSS 4.7
CVE-2026-2455 MEDIUM
SSRF bypass via IPv4-mapped IPv6 literals
CVSS 4.3
CVE-2026-4231 HIGH
vanna-ai vanna Endpoint __init__.py run_sql server-side request forgery
CVSS 7.3
CVE-2026-4215 MEDIUM
FlowCI flow-core-x SMTP Host ConfigServiceImpl.java save server-side request forgery
CVSS 6.3
Details
Vulnerabilities 2,683