CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,678 vulnerabilities with CWE-918
CVE-2026-43995
CRITICAL
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
CVSS 9.8
CVE-2026-42860
HIGH
Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint
CVSS 8.5
CVE-2026-42858
HIGH
Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint
CVSS 8.5
CVE-2026-42313
HIGH
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy
CVSS 8.3
CVE-2026-3048
MEDIUM
Nexus Repository 3 - Improper LDAP Referral Handling
CVE-2026-2393
HIGH
Server-Side Request Forgery (SSRF) in mlflow/mlflow
CVSS 7.1
CVE-2026-8193
MEDIUM
Akaunting Invoice PDF Rendering dompdf.php server-side request forgery
CVSS 6.3
CVE-2026-44313
CRITICAL
LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function
CVSS 9.1
CVE-2026-44286
LOW
FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation
CVE-2026-44284
MEDIUM
FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution
CVSS 6.3
CVE-2026-42352
HIGH
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
CVSS 8.6
CVE-2026-42346
MEDIUM
Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation paths
CVSS 6.5
CVE-2026-42345
HIGH
FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot
CVSS 7.7
CVE-2026-42339
HIGH
New API <= 0.11.9-alpha.1 - Server-Side Request Forgery Filter Bypass
CVSS 7.1
CVE-2026-41682
MEDIUM
pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion
CVE-2026-42213
MEDIUM
SolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leak
CVE-2026-44694
CRITICAL
n8n-MCP: Authenticated SSRF in n8n-mcp webhook and API client paths
CVSS 9.1
CVE-2026-42181
MEDIUM
Lemmy: SSRF and internal image disclosure in post link metadata via unvalidated og:image
CVSS 6.5
CVE-2026-42180
MEDIUM
Lemmy: SSRF in /api/v3/post via Webmention dispatch
CVSS 6.3
CVE-2026-41887
MEDIUM
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
CVSS 4.9
CVE-2026-42353
HIGH
Path traversal / SSRF in i18next-http-middleware via user-controlled language and namespace parameters
CVSS 8.2
CVE-2026-44335
CRITICAL
SSRF bypass in PraisonAI
CVSS 9.8
CVE-2026-41423
MEDIUM
Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server
CVSS 5.3
CVE-2026-42261
HIGH
PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`
CVSS 7.1
CVE-2026-8034
CRITICAL
Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion
CVSS 9.8
Details
Vulnerabilities
2,678