CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

3,003 vulnerabilities with CWE-918
CVE-2026-53727 HIGH
css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
CVE-2026-16074 MEDIUM
AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery
CVSS 6.3
CVE-2026-7754 HIGH
IBM Langflow OSS - SSRF Protection Configuration Vulnerability
CVSS 7.7
CVE-2026-51833 HIGH
XenForo 2.3.8 - Authenticated Server-Side Request Forgery via RSS Feed Management
CVSS 7.5
CVE-2026-50151 HIGH
oras-go: credential forwarding via unvalidated Location header in blob upload
CVSS 7.5
CVE-2026-48978 LOW
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
CVE-2026-63096 MEDIUM
Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVSS 5.8
CVE-2026-16016 HIGH
poco-ai poco-claw task.py run_task server-side request forgery
CVSS 7.3
CVE-2026-62234 HIGH
Grav < 2.0.4 SSRF via Unrestricted cURL Protocols
CVSS 8.1
CVE-2026-62227 HIGH
OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot
CVSS 7.7
CVE-2026-62226 HIGH
OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route
CVSS 8.5
CVE-2026-62216 MEDIUM
OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload
CVSS 5.0
CVE-2026-62201 HIGH
OpenClaw < 2026.6.6 Network Policy Bypass via exec-server
CVSS 7.7
CVE-2026-44023 HIGH
Docling Core has unsafe remote filename resolution
CVSS 8.6
CVE-2026-46404 MEDIUM
BigBlueButton: Presentation URL Security Hardening
CVSS 6.8
CVE-2026-63088 HIGH
stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass
CVSS 8.6
CVE-2026-63086 HIGH
text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions
CVSS 8.6
CVE-2026-59867 HIGH
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVSS 7.1
CVE-2026-63306 HIGH
stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints
CVSS 8.6
CVE-2026-53446 MEDIUM
Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs
CVE-2026-56678 MEDIUM
9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
CVSS 6.4
CVE-2026-15746 MEDIUM
Credential disclosure in Strands Agents Tools elasticsearch_memory tool
CVSS 6.5
CVE-2026-53513 CRITICAL
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
CVSS 9.6
CVE-2026-47160 MEDIUM
Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
CVSS 5.8
CVE-2026-45806 HIGH
Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url
CVSS 7.7
Details
Vulnerabilities 3,003