CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,678 vulnerabilities with CWE-918
CVE-2026-43995 CRITICAL
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
CVSS 9.8
CVE-2026-42860 HIGH
Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint
CVSS 8.5
CVE-2026-42858 HIGH
Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint
CVSS 8.5
CVE-2026-42313 HIGH
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy
CVSS 8.3
CVE-2026-3048 MEDIUM
Nexus Repository 3 - Improper LDAP Referral Handling
CVE-2026-2393 HIGH
Server-Side Request Forgery (SSRF) in mlflow/mlflow
CVSS 7.1
CVE-2026-8193 MEDIUM
Akaunting Invoice PDF Rendering dompdf.php server-side request forgery
CVSS 6.3
CVE-2026-44313 CRITICAL
LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function
CVSS 9.1
CVE-2026-44286 LOW
FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation
CVE-2026-44284 MEDIUM
FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution
CVSS 6.3
CVE-2026-42352 HIGH
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
CVSS 8.6
CVE-2026-42346 MEDIUM
Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation paths
CVSS 6.5
CVE-2026-42345 HIGH
FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot
CVSS 7.7
CVE-2026-42339 HIGH
New API <= 0.11.9-alpha.1 - Server-Side Request Forgery Filter Bypass
CVSS 7.1
CVE-2026-41682 MEDIUM
pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion
CVE-2026-42213 MEDIUM
SolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leak
CVE-2026-44694 CRITICAL
n8n-MCP: Authenticated SSRF in n8n-mcp webhook and API client paths
CVSS 9.1
CVE-2026-42181 MEDIUM
Lemmy: SSRF and internal image disclosure in post link metadata via unvalidated og:image
CVSS 6.5
CVE-2026-42180 MEDIUM
Lemmy: SSRF in /api/v3/post via Webmention dispatch
CVSS 6.3
CVE-2026-41887 MEDIUM
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
CVSS 4.9
CVE-2026-42353 HIGH
Path traversal / SSRF in i18next-http-middleware via user-controlled language and namespace parameters
CVSS 8.2
CVE-2026-44335 CRITICAL
SSRF bypass in PraisonAI
CVSS 9.8
CVE-2026-41423 MEDIUM
Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server
CVSS 5.3
CVE-2026-42261 HIGH
PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`
CVSS 7.1
CVE-2026-8034 CRITICAL
Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion
CVSS 9.8
Details
Vulnerabilities 2,678