CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,834 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 1 of 77
- CVE-2026-83548CRITICALCVSS 10.0EG 10.0⚠ KEV2026-09-01
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized ac…
- CVE-2026-15409CRITICALCVSS 10.0EG 10.0⚠ KEV2026-07-14
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- CVE-2026-49869CRITICALCVSS 10.0EG 10.0⚠ KEV2026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Becau…
- CVE-2021-27561CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-15
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
- CVE-2021-34473CRITICALCVSS 9.8EG 9.8⚠ KEV2021-07-14
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-22175CRITICALCVSS 9.8EG 9.8⚠ KEV2021-06-11
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instan…
- CVE-2021-21985CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-26
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port …
- CVE-2021-22986CRITICALCVSS 9.8EG 9.8⚠ KEV2021-03-31
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an un…
- CVE-2021-26855CRITICALCVSS 9.8EG 9.8⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-27103CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-16
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
- CVE-2020-7796CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-18
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
- CVE-2026-64849CRITICALCVSS 9.3EG 9.3⚠ KEV2026-08-17
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_we…
- CVE-2021-40438CRITICALCVSS 9.0EG 9.0⚠ KEV2021-09-16
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- CVE-2022-41040CRITICALCVSS 8.8EG 9.0⚠ KEV2022-10-03
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-20230CRITICALCVSS 8.6EG 9.0⚠ KEV2026-06-03
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forger…
- CVE-2024-21893CRITICALCVSS 8.2EG 9.0⚠ KEV2024-01-31
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authen…
- CVE-2025-61884CRITICALCVSS 7.5EG 9.0⚠ KEV2025-10-12
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network ac…
- CVE-2021-22054CRITICALCVSS 7.5EG 9.0⚠ KEV2021-12-17
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to …
- CVE-2021-21975CRITICALCVSS 7.5EG 9.0⚠ KEV2021-03-31
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal a…
- CVE-2019-9621CRITICALCVSS 7.5EG 9.0⚠ KEV2019-04-30
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
- CVE-2021-21311CRITICALCVSS 7.2EG 9.0⚠ KEV2021-02-11
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) ar…
- CVE-2021-39935CRITICALCVSS 6.8EG 9.0⚠ KEV2021-12-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform S…
- CVE-2016-3718CRITICALCVSS 5.5EG 9.0⚠ KEV2016-05-05
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
- CVE-2023-41763CRITICALCVSS 5.3EG 9.0⚠ KEV2023-10-10
Skype for Business Elevation of Privilege Vulnerability
- CVE-2021-21973CRITICALCVSS 5.3EG 9.0⚠ KEV2021-02-24
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a PO…
- CVE-2026-102255CRITICALCVSS 10.0EG 10.02026-10-07
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability t…
- CVE-2026-83660CRITICALCVSS 10.0EG 10.02026-09-22
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
- CVE-2026-54734CRITICALCVSS 10.0EG 10.02026-09-17
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A ma…
- CVE-2026-92808CRITICALCVSS 10.0EG 10.02026-09-16
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's …
- CVE-2026-75754CRITICALCVSS 10.0EG 10.02026-09-04
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local servic…
- CVE-2026-54745CRITICALCVSS 10.0EG 10.02026-08-28
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ …
- CVE-2026-76193CRITICALCVSS 10.0EG 10.02026-08-25
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitr…
- CVE-2026-69502CRITICALCVSS 10.0EG 10.02026-08-21
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-65801CRITICALCVSS 10.0EG 10.02026-08-20
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-48331CRITICALCVSS 10.0EG 10.02026-08-03
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
- CVE-2026-54735CRITICALCVSS 10.0EG 10.02026-07-29
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without prop…
- CVE-2026-57106CRITICALCVSS 10.0EG 10.02026-07-24
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-62643CRITICALCVSS 10.0EG 10.02026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. N…
- CVE-2026-57211CRITICALCVSS 10.0EG 10.02026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path val…
- CVE-2026-13773CRITICALCVSS 10.0EG 10.02026-06-30
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turni…
- CVE-2026-2053CRITICALCVSS 10.0EG 10.02026-06-26
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing heade…
- CVE-2026-47938CRITICALCVSS 10.0EG 10.02026-06-09
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. …
- CVE-2026-33712CRITICALCVSS 10.0EG 10.02026-05-22
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a cust…
- CVE-2026-42043CRITICALCVSS 10.0EG 10.02026-04-24
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completel…
- CVE-2026-35431CRITICALCVSS 10.0EG 10.02026-04-23
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-28798CRITICALCVSS 10.0EG 10.02026-04-03
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain usi…
- CVE-2026-32871CRITICALCVSS 10.0EG 10.02026-04-02
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constru…
- CVE-2026-34162CRITICALCVSS 10.0EG 10.02026-03-31
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a …
- CVE-2026-32169CRITICALCVSS 10.0EG 10.02026-03-19
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-64180CRITICALCVSS 10.0EG 10.02025-11-07
Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DN…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →