CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,678 vulnerabilities with CWE-918
CVE-2026-45412
MEDIUM
MaxKB: Unauthenticated SSRF via Workflow Template Import
CVE-2026-42336
MEDIUM
MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch
CVE-2026-42335
MEDIUM
MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy
CVE-2026-44502
MEDIUM
Bugsink: SSRF bypass in `validate_webhook_url`
CVSS 4.3
CVE-2026-2264
CRITICAL
Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.
CVE-2026-43936
MEDIUM
e107: Server-Side Request Forgery (SSRF) in the remote file fetcher
CVSS 4.3
CVE-2026-40564
MEDIUM
Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator
CVSS 6.5
CVE-2026-45082
HIGH
Karakeep <0.32.0 Redirect Handling - Server-Side Request Forgery Bypass
CVSS 7.6
CVE-2026-44598
MEDIUM
Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)
CVSS 5.4
CVE-2026-48843
HIGH
Roundcube Webmail - Server-Side Request Forgery (SSRF)
CVSS 7.2
CVE-2026-9464
MEDIUM
YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery
CVSS 4.7
CVE-2026-47076
MEDIUM
SSRF allowlist bypass via percent-encoded host in hackney
CVSS 6.5
CVE-2026-9372
HIGH
ItzCrazyKns Vane Model Provider API route.ts server-side request forgery
CVSS 7.3
CVE-2026-9304
MEDIUM
calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery
CVSS 5.0
CVE-2026-39965
HIGH
TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks
CVSS 7.7
CVE-2026-34207
HIGH
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
CVSS 7.6
CVE-2026-33712
CRITICAL
TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls
CVSS 10.0
CVE-2026-7325
HIGH
Devolutions Server - Server-Side Request Forgery (SSRF)
CVSS 7.1
CVE-2026-7798
MEDIUM
FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter
CVSS 5.4
CVE-2026-7890
MEDIUM
Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block
CVSS 6.4
CVE-2026-6394
MEDIUM
Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter
CVSS 5.4
CVE-2026-33637
NONE
Faraday: Protocol-relative URI objects still bypass host scoping (possible incomplete fix for GHSA-33mh-2634-fwr2)
CVE-2026-47358
HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-47357
HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-47356
HIGH
Terrascan < 1.18.3 - Unauthenticated Server-Side Request Forgery via Webhook URL Parameter
CVSS 7.5
Details
Vulnerabilities
2,678