CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,683 vulnerabilities with CWE-918
CVE-2026-26118 HIGH
Azure MCP Server - Authenticated Server-Side Request Forgery
CVSS 8.8
CVE-2026-24316 MEDIUM
SAP NetWeaver Application Server for ABAP - Server-Side Request Forgery via ABAP Test Report
CVSS 6.4
CVE-2026-25960 HIGH
vLLM 0.15.1-0.17.0 - Server-Side Request Forgery via URL Parsing Inconsistency
CVSS 7.1
CVE-2026-25737 HIGH
Budibase <=3.24.0 - Arbitrary File Upload
CVSS 8.9
CVE-2026-3588 HIGH
IKEA Dirigera < 2.866.4 - Server-Side Request Forgery
CVSS 7.5
CVE-2026-3789 MEDIUM
Bytedesk <= 1.3.9 - Server-Side Request Forgery via SpringAIGitee apiUrl
CVSS 6.3
CVE-2026-3788 MEDIUM
bytedesk < 1.4.5.4 - Server-Side Request Forgery via SpringAIOpenrouterRestController getModels Function
CVSS 6.3
CVE-2026-3750 MEDIUM
continew_admin < 4.1.0 - Server-Side Request Forgery via S3ClientFactory URI.create
CVSS 4.7
CVE-2026-3733 MEDIUM
xxl-job <= 3.3.2 - Server-Side Request Forgery
CVSS 6.3
CVE-2026-3683 MEDIUM
HotGo <= 2.0 - Server-Side Request Forgery via ImageTransferStorage Function
CVSS 6.3
CVE-2026-3681 MEDIUM
FFmate <= 2.0.15 - Server-Side Request Forgery via fireWebhook Function
CVSS 6.3
CVE-2026-30858 MEDIUM
WeKnora < 0.3.0 - Unauthenticated Server-Side Request Forgery via DNS Rebinding
CVSS 6.5
CVE-2026-30834 HIGH
PinchTab < 0.7.7 - Server-Side Request Forgery via Download Endpoint
CVSS 7.5
CVE-2026-30832 CRITICAL
Soft Serve 0.6.0-0.11.3 - Authenticated Server-Side Request Forgery via LFS Endpoint URL
CVSS 9.1
CVE-2026-30840 HIGH
wallos < 4.6.2 - Server-Side Request Forgery via Notification Tester
CVSS 8.8
CVE-2026-30839 MEDIUM
wallos < 4.6.2 - Server-Side Request Forgery via testwebhooknotifications.php
CVSS 4.3
CVE-2026-30828 HIGH
wallos < 4.6.2 - Server-Side Request Forgery via URL Parameter
CVSS 7.5
CVE-2026-27797 MEDIUM
homarr < 1.54.0 - Unauthenticated Server-Side Request Forgery
CVSS 5.3
CVE-2026-30247 MEDIUM
WeKnora < 0.2.12 - Server-Side Request Forgery via Redirect Chain Bypass
CVSS 5.9
CVE-2026-30242 HIGH
Plane < 1.2.3 - Authenticated Server-Side Request Forgery via Webhook URL Validation Bypass
CVSS 8.5
CVE-2026-30844 HIGH
Wekan 8.32-8.33 - Authenticated Server-Side Request Forgery via Attachment URL Loading
CVSS 8.1
CVE-2026-29178 HIGH
Lemmy < 0.19.16 - Unauthenticated Server-Side Request Forgery via Image Endpoint File Type Parameter
CVE-2026-29049 MEDIUM
melange < 0.40.5 - Server-Side Request Forgery via Unbounded URI Download
CVSS 4.3
CVE-2026-28680 CRITICAL
ghostfolio < 2.245.0 - Server-Side Request Forgery via Manual Asset Import Feature
CVSS 9.3
CVE-2026-28677 HIGH
OpenSift < 1.6.3 - Server-Side Request Forgery via URL Ingest Pipeline
CVSS 8.2
Details
Vulnerabilities 2,683