CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
3,003 vulnerabilities with CWE-918
CVE-2026-61835
HIGH
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
CVSS 7.7
CVE-2026-61646
MEDIUM
FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects
CVE-2026-54562
MEDIUM
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
CVSS 6.5
CVE-2026-61430
HIGH
PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl
CVSS 8.5
CVE-2026-48290
HIGH
CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)
CVSS 8.2
CVE-2026-15750
MEDIUM
mastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.ts z.string server-side request forgery
CVSS 6.3
CVE-2026-61520
HIGH
SimpleMachines - Simple Machines Forum SSRF via Image Proxy
CVSS 7.7
CVE-2026-48332
HIGH
Adobe ColdFusion 2025 - ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
CVSS 7.7
CVE-2026-24234
MEDIUM
Nvidia TensorRT-LLM < v1.3.0 rc16 - Server-Side Request Forgery (SSRF)
CVSS 6.8
CVE-2026-15643
HIGH
AWS HealthLake MCP Server SSRF via Pagination URL
CVSS 7.3
CVE-2026-48736
HIGH
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
CVSS 8.6
CVE-2026-48259
CRITICAL
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
CVSS 9.6
CVE-2026-15409
CRITICAL
KEV
Sonicwall SMA1000 - Server-Side Request Forgery (SSRF)
CVSS 10.0
CVE-2026-55051
MEDIUM
Microsoft SharePoint Server Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-14646
MEDIUM
Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect
CVE-2026-14645
MEDIUM
Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability
CVE-2026-7494
MEDIUM
Nexus Repository - SSRF in SSL Certificate Retrieval
CVE-2026-62643
HIGH
Roundcube Webmail - Server-Side Request Forgery (SSRF)
CVSS 7.2
CVE-2026-52840
LOW
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
CVSS 2.7
CVE-2026-58478
MEDIUM
Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL
CVSS 6.5
CVE-2026-15183
CRITICAL
Input Validation Vulnerabilities in Snowflake Spark Connector
CVE-2026-15668
MEDIUM
louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery
CVSS 6.3
CVE-2026-15628
MEDIUM
zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to_data_url server-side request forgery
CVSS 6.3
CVE-2026-15624
MEDIUM
nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery
CVSS 6.3
CVE-2026-15620
MEDIUM
mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery
CVSS 6.3
Details
Vulnerabilities
3,003