CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
3,003 vulnerabilities with CWE-918
CVE-2026-53727
HIGH
css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
CVE-2026-16074
MEDIUM
AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery
CVSS 6.3
CVE-2026-7754
HIGH
IBM Langflow OSS - SSRF Protection Configuration Vulnerability
CVSS 7.7
CVE-2026-51833
HIGH
XenForo 2.3.8 - Authenticated Server-Side Request Forgery via RSS Feed Management
CVSS 7.5
CVE-2026-50151
HIGH
oras-go: credential forwarding via unvalidated Location header in blob upload
CVSS 7.5
CVE-2026-48978
LOW
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
CVE-2026-63096
MEDIUM
Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVSS 5.8
CVE-2026-16016
HIGH
poco-ai poco-claw task.py run_task server-side request forgery
CVSS 7.3
CVE-2026-62234
HIGH
Grav < 2.0.4 SSRF via Unrestricted cURL Protocols
CVSS 8.1
CVE-2026-62227
HIGH
OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot
CVSS 7.7
CVE-2026-62226
HIGH
OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route
CVSS 8.5
CVE-2026-62216
MEDIUM
OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload
CVSS 5.0
CVE-2026-62201
HIGH
OpenClaw < 2026.6.6 Network Policy Bypass via exec-server
CVSS 7.7
CVE-2026-44023
HIGH
Docling Core has unsafe remote filename resolution
CVSS 8.6
CVE-2026-46404
MEDIUM
BigBlueButton: Presentation URL Security Hardening
CVSS 6.8
CVE-2026-63088
HIGH
stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass
CVSS 8.6
CVE-2026-63086
HIGH
text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions
CVSS 8.6
CVE-2026-59867
HIGH
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVSS 7.1
CVE-2026-63306
HIGH
stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints
CVSS 8.6
CVE-2026-53446
MEDIUM
Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs
CVE-2026-56678
MEDIUM
9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
CVSS 6.4
CVE-2026-15746
MEDIUM
Credential disclosure in Strands Agents Tools elasticsearch_memory tool
CVSS 6.5
CVE-2026-53513
CRITICAL
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
CVSS 9.6
CVE-2026-47160
MEDIUM
Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
CVSS 5.8
CVE-2026-45806
HIGH
Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url
CVSS 7.7
Details
Vulnerabilities
3,003