CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,834 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 2 of 77
- CVE-2025-53767CRITICALCVSS 10.0EG 10.02025-08-07
Azure OpenAI Elevation of Privilege Vulnerability
- CVE-2025-54122CRITICALCVSS 10.0EG 10.02025-07-21
Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager Desktop and Server edition versions up to a…
- CVE-2025-2828CRITICALCVSS 10.0EG 10.02025-06-23
A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain vers…
- CVE-2024-42467CRITICALCVSS 10.0EG 10.02024-08-12
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentica…
- CVE-2023-39967CRITICALCVSS 10.0EG 10.02023-09-06
WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance.…
- CVE-2023-3432CRITICALCVSS 10.0EG 10.02023-06-27
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
- CVE-2022-21215CRITICALCVSS 10.0EG 10.02022-02-18
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselv…
- CVE-2021-29475CRITICALCVSS 10.0EG 10.02021-04-26
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note conte…
- CVE-2021-27329CRITICALCVSS 10.0EG 10.02021-02-18
Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
- CVE-2019-16932CRITICALCVSS 10.0EG 10.02019-09-30
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
- CVE-2019-13020CRITICALCVSS 10.0EG 10.02019-08-26
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the brows…
- CVE-2016-10927CRITICALCVSS 10.0EG 10.02019-08-22
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
- CVE-2016-10926CRITICALCVSS 10.0EG 10.02019-08-22
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
- CVE-2019-12153CRITICALCVSS 10.0EG 10.02019-06-11
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
- CVE-2019-9174CRITICALCVSS 10.0EG 10.02019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.
- CVE-2019-10686CRITICALCVSS 10.0EG 10.02019-04-01
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
- CVE-2019-3905CRITICALCVSS 10.0EG 10.02019-01-03
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
- CVE-2018-14721CRITICALCVSS 10.0EG 10.02019-01-02
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
- CVE-2018-18843CRITICALCVSS 10.0EG 10.02018-12-04
The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.
- CVE-2018-19047CRITICALCVSS 10.0EG 10.02018-11-07
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maint…
- CVE-2018-10511CRITICALCVSS 10.0EG 10.02018-08-15
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
- CVE-2018-3774CRITICALCVSS 10.0EG 10.02018-08-12
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
- CVE-2018-1000124CRITICALCVSS 10.0EG 10.02018-03-13
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack…
- CVE-2017-11291CRITICALCVSS 10.0EG 10.02017-12-09
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.
- CVE-2017-12905CRITICALCVSS 10.0EG 10.02017-09-25
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
- CVE-2017-8794CRITICALCVSS 10.0EG 10.02017-05-05
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///e…
- CVE-2026-33107CRITICALCVSS 9.8EG 10.02026-04-03
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-105636CRITICALCVSS 9.9EG 9.92026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url()…
- CVE-2026-82013CRITICALCVSS 9.9EG 9.92026-09-22
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resour…
- CVE-2026-82443CRITICALCVSS 9.9EG 9.92026-09-22
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resour…
- CVE-2026-89049CRITICALCVSS 9.9EG 9.92026-09-10
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms mi…
- CVE-2026-65818CRITICALCVSS 9.9EG 9.92026-09-03
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69851CRITICALCVSS 9.9EG 9.92026-08-20
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45262CRITICALCVSS 9.9EG 9.92026-07-14
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` ## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:80…
- CVE-2026-57100CRITICALCVSS 9.9EG 9.92026-07-02
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45499CRITICALCVSS 9.9EG 9.92026-07-02
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
- CVE-2026-55115CRITICALCVSS 9.9EG 9.92026-07-02
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
- CVE-2026-55166CRITICALCVSS 9.9EG 9.92026-06-25
Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend reque…
- CVE-2026-43986CRITICALCVSS 9.9EG 9.92026-06-04
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the s…
- CVE-2026-9813CRITICALCVSS 9.9EG 9.92026-05-28
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the applicatio…
- CVE-2026-56348CRITICALCVSS 9.9EG 9.92026-05-19
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential ac…
- CVE-2026-42864CRITICALCVSS 9.9EG 9.92026-05-11
FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permissions.AllowAny]). Its attachments …
- CVE-2026-40089CRITICALCVSS 9.9EG 9.92026-04-09
Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Inst…
- CVE-2025-62718CRITICALCVSS 9.9EG 9.92026-04-09
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trail…
- CVE-2026-31818CRITICALCVSS 9.9EG 9.92026-04-03
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered c…
- CVE-2026-26137CRITICALCVSS 9.9EG 9.92026-03-19
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
- CVE-2025-68662CRITICALCVSS 9.9EG 9.92026-01-28
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is…
- CVE-2026-22039CRITICALCVSS 9.9EG 9.92026-01-27
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed usi…
- CVE-2025-64663CRITICALCVSS 9.9EG 9.92025-12-18
Custom Question Answering Elevation of Privilege Vulnerability
- CVE-2025-64709CRITICALCVSS 9.9EG 9.92025-11-13
Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTT…
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →