← Back to feed Search feed

CWE-918 Server-Side Request Forgery (SSRF) vulnerabilities

121 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unCRITICAL10.025%ileNVD2026-09-16
CVE-2026-54734Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplCRITICAL10.030%ileNVD2026-09-17
CVE-2026-68536Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affectCRITICAL9.840%ileNVD2026-09-16
CVE-2025-56563A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts CRITICAL9.834%ileNVD2026-09-16
CVE-2026-12944IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) CRITICAL9.616%ileNVD2026-09-14
CVE-2026-61559`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1CRITICAL9.620%ileNVD2026-09-15
CVE-2026-67101HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionalCRITICAL9.319%ileNVD2026-09-18
CVE-2026-92576HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the CRITICAL9.234%ileNVD2026-09-16
CVE-2026-88592kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFiCRITICAL9.18%ileNVD2026-09-16
CVE-2026-77866Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reacCRITICAL9.039%ileNVD2026-09-15
CVE-2026-92566DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that aHIGH8.841%ileNVD2026-09-16
CVE-2026-91935Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect HIGH8.720%ileNVD2026-09-15
CVE-2026-58201Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2HIGH8.720%ileNVD2026-09-15
CVE-2026-92719Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing atHIGH8.736%ileNVD2026-09-16
CVE-2026-92815changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attacHIGH8.735%ileNVD2026-09-16
CVE-2026-54628Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtuHIGH8.628%ileNVD2026-09-14
CVE-2026-73247Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadataHIGH8.631%ileGitHub2026-09-17
CVE-2026-57126PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blockHIGH8.532%ileNVD2026-09-14
CVE-2026-59973FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 aHIGH8.532%ileNVD2026-09-15
CVE-2026-76680Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low priviHIGH8.521%ileNVD2026-09-15
CVE-2026-54507Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5HIGH8.425%ileNVD2026-09-17
CVE-2026-90769Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated usHIGH8.318%ileNVD2026-09-13
CVE-2026-91923KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoinHIGH8.319%ileNVD2026-09-15
CVE-2026-91943Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_HIGH8.324%ileNVD2026-09-15
CVE-2026-63443Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10HIGH8.336%ileNVD2026-09-15
CVE-2026-54549Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, thHIGH8.314%ileNVD2026-09-15
CVE-2025-69299WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerabilityHIGH8.39%ileMicrosoft2026-02-10
CVE-2026-79425An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allowsHIGH8.126%ileNVD2026-09-15
CVE-2026-55864GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/toolHIGH7.847%ileNVD2026-09-15
CVE-2026-53957Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-serHIGH7.717%ileNVD2026-09-15
CVE-2026-76820OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0HIGH7.723%ileNVD2026-09-15
CVE-2026-54339Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passeHIGH7.727%ileNVD2026-09-17
CVE-2026-91938Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer HIGH7.628%ileNVD2026-09-15
CVE-2026-76425A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks HIGH7.622%ileNVD2026-09-16
CVE-2026-85917Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netwHIGH7.545%ileNVD2026-09-17
GHSA-39wr-7q6h-cf68LMDeploy has an SSRF bypassHIGH7.5GitHub2026-09-18
CVE-2026-81446Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerabHIGH7.430%ileNVD2026-09-17
CVE-2026-54544Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbouHIGH7.225%ileNVD2026-09-15
CVE-2026-54166Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` pHIGH7.117%ileNVD2026-09-11
CVE-2026-91750WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url enHIGH7.119%ileNVD2026-09-15
CVE-2026-54077ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/querHIGH7.131%ileNVD2026-09-15
CVE-2026-58485mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through HIGH7.13%ileNVD2026-09-15
CVE-2026-92602TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigControHIGH7.123%ileNVD2026-09-16
CVE-2026-92775Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetchesHIGH7.123%ileNVD2026-09-16
CVE-2026-92789Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate afterHIGH7.123%ileNVD2026-09-16
CVE-2026-92795Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticateHIGH7.115%ileNVD2026-09-16
CVE-2026-92804Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token HIGH7.120%ileNVD2026-09-16
CVE-2026-86862pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbnHIGH7.110%ileNVD2026-09-17
CVE-2026-71198In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to HIGH7.038%ileNVD2026-09-14
CVE-2026-71196OSSA-2026-038: Multiple SSRF vulnerabilities in Glance web-download and HTTP image APIsHIGH7.0OpenStack2026-09-03
CVE-2026-91081Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymousMEDIUM6.916%ileNVD2026-09-14
CVE-2026-91966AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availabilityMEDIUM6.932%ileNVD2026-09-15
CVE-2026-92215A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.gMEDIUM6.932%ileNVD2026-09-16
CVE-2026-92813Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unaMEDIUM6.922%ileNVD2026-09-16
CVE-2026-61793Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenMEDIUM6.939%ileNVD2026-09-17
CVE-2026-53708ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MMEDIUM6.615%ileNVD2026-09-14
CVE-2026-57115PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the iniMEDIUM6.518%ileNVD2026-09-14
CVE-2026-73497MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0MEDIUM6.514%ileNVD2026-09-14
CVE-2026-12765IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticMEDIUM6.512%ileNVD2026-09-14
CVE-2026-12767IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticMEDIUM6.512%ileNVD2026-09-14
CVE-2026-54688mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through MEDIUM6.530%ileNVD2026-09-15
CVE-2026-92139Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includinMEDIUM6.522%ileNVD2026-09-16
CVE-2026-87116Tanium addressed a server-side request forgery vulnerability in Threat Response.MEDIUM6.516%ileNVD2026-09-16
CVE-2026-62282OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack intMEDIUM6.5NVD2026-09-18
CVE-2026-57211RabbitMQ: UNC SSRF affecting the management UI on WindowsMEDIUM6.549%ileMicrosoft2026-07-14
CVE-2026-48858ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksMEDIUM6.515%ileMicrosoft2026-06-09
CVE-2026-66608Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= MEDIUM6.46%ileNVD2026-09-17
CVE-2026-81443Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerabMEDIUM6.414%ileNVD2026-09-17
CVE-2026-12106The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, MEDIUM6.416%ileNVD2026-09-18
CVE-2026-13318Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ipMEDIUM6.415%ileMicrosoft2026-06-09
CVE-2026-54452safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits theMEDIUM6.333%ileNVD2026-09-14
CVE-2026-91079Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hMEDIUM6.329%ileNVD2026-09-14
CVE-2026-54689mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through MEDIUM6.33%ileNVD2026-09-15
CVE-2026-55073WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restriMEDIUM6.29%ileNVD2026-09-14
CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instaMEDIUM6.23%ileNVD2026-09-18
CVE-2026-55591Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in srMEDIUM5.820%ileNVD2026-09-15
CVE-2026-90984The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetchMEDIUM5.83%ileNVD2026-09-18
CVE-2026-86144In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This haMEDIUM5.68%ileMicrosoft2026-09-08
CVE-2026-90710A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file coMEDIUM5.540%ileNVD2026-09-14
CVE-2026-54637Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduleMEDIUM5.541%ileNVD2026-09-15
CVE-2026-92380A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreMEDIUM5.540%ileNVD2026-09-16
CVE-2026-15887IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requMEDIUM5.48%ileNVD2026-09-14
CVE-2026-12766IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticatMEDIUM5.48%ileNVD2026-09-14
CVE-2026-70367Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to looMEDIUM5.45%ileMicrosoft2026-08-11
CVE-2026-49865Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerMEDIUM5.326%ileNVD2026-09-11
CVE-2026-90446An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path oMEDIUM5.311%ileNVD2026-09-11
CVE-2026-90486A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by thMEDIUM5.315%ileNVD2026-09-12
CVE-2026-90790A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notMEDIUM5.312%ileNVD2026-09-14
CVE-2026-91199Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetchMEDIUM5.310%ileNVD2026-09-14
CVE-2026-44202Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListeneMEDIUM5.325%ileNVD2026-09-15
CVE-2026-91967AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL functiMEDIUM5.326%ileNVD2026-09-15
CVE-2026-92184A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of thMEDIUM5.320%ileNVD2026-09-16
CVE-2026-92568MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allowsMEDIUM5.322%ileNVD2026-09-16
CVE-2026-92569Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fMEDIUM5.320%ileNVD2026-09-16
CVE-2026-59823LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated MEDIUM5.338%ileNVD2026-09-16
CVE-2026-54918NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the aMEDIUM5.323%ileNVD2026-09-17
CVE-2026-93597ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE andMEDIUM5.3NVD2026-09-18
CVE-2026-93506A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/MEDIUM5.3NVD2026-09-18
CVE-2026-92932In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error inMEDIUM5.114%ileNVD2026-09-17
CVE-2026-54546CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.MEDIUM5.020%ileNVD2026-09-17
CVE-2026-48737pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pMEDIUM4.98%ileNVD2026-09-15
CVE-2026-55374canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrMEDIUM4.814%ileNVD2026-09-15
CVE-2026-58196ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior MEDIUM4.731%ileNVD2026-09-15
CVE-2026-85732oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go aMEDIUM4.732%ileNVD2026-09-16
CVE-2026-54565rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox eMEDIUM4.73%ileNVD2026-09-17
CVE-2026-40537A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-MEDIUM4.317%ileNVD2026-09-18
CVE-2026-48522PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemesMEDIUM4.213%ileMicrosoft2026-05-12
CVE-2026-76559The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during tMEDIUM4.121%ileNVD2026-09-16
CVE-2026-19504Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to discloseMEDIUM4.02%ileNVD2026-09-15
CVE-2026-93384Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker lLOW3.712%ileNVD2026-09-17
CVE-2026-54450ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior LOW2.925%ileNVD2026-09-15
CVE-2026-90580A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the fiLOW2.114%ileNVD2026-09-13
CVE-2026-90814A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function gitLOW2.112%ileNVD2026-09-14
CVE-2026-90818A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the fLOW2.142%ileNVD2026-09-14
CVE-2026-18424Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a hLOW2.122%ileNVD2026-09-15
CVE-2026-92527A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controllLOW2.129%ileNVD2026-09-16
CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allUNKNOWN4%ileNVD2026-09-15
CVE-2026-8328FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addressUNKNOWN39%ileMicrosoft2026-05-12
CVE-2026-46683Snappy: SSRF and local file read via the xsl-style-sheet optionUNKNOWN17%ileMicrosoft2026-06-09
CVE-2026-50221OSSA-2026-024: Swift proxy-server SSRF via header injectionUNKNOWN4%ileOpenStack2026-06-23
FG-IR-26-159Server-Side Request Forgery (SSRF)UNKNOWNFortinet2026-08-12