← Back to feed Search feed

CWE-918 Server-Side Request Forgery (SSRF) vulnerabilities

74 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-54735Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0CRITICAL10.028%ileNVD2026-07-29
CVE-2026-48331Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privCRITICAL10.038%ileNVD2026-08-03
CVE-2026-54725vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1CRITICAL9.624%ileNVD2026-07-31
CVE-2026-14529IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 tCRITICAL9.426%ileNVD2026-07-29
CVE-2026-67426Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verificaCRITICAL9.321%ileNVD2026-07-29
CVE-2026-18353PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer aHIGH8.815%ileNVD2026-07-30
CVE-2026-69078CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functioHIGH8.822%ileNVD2026-08-03
CVE-2026-54722DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_HIGH8.725%ileNVD2026-07-30
CVE-2026-54729DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_HIGH8.722%ileNVD2026-07-31
CVE-2026-15307An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parseHIGH8.7NVD2026-08-04
CVE-2026-14869The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTHIGH8.622%ileNVD2026-07-28
CVE-2026-16328In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing HIGH8.614%ileNVD2026-07-29
CVE-2026-67425Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys HIGH8.624%ileNVD2026-07-29
CVE-2026-12075Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.loaHIGH8.6GitHub2026-07-31
CVE-2026-67424Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, htHIGH8.515%ileNVD2026-07-29
CVE-2026-67428Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includiHIGH8.526%ileNVD2026-07-29
CVE-2026-69250Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 tokeHIGH8.5NVD2026-08-04
CVE-2026-57862Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypassHIGH8.422%ileNVD2026-07-30
CVE-2026-66415Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated aHIGH8.421%ileNVD2026-07-30
CVE-2026-67436Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. InHIGH8.316%ileNVD2026-07-29
CVE-2026-14980IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which cHIGH8.313%ileNVD2026-07-30
CVE-2026-54690datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH8.211%ileNVD2026-07-28
CVE-2026-54691datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_coHIGH8.211%ileNVD2026-07-28
CVE-2026-58189Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. THIGH8.239%ileNVD2026-07-29
CVE-2026-53500Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passesHIGH8.221%ileNVD2026-07-31
CVE-2026-67311Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that failHIGH8.217%ileNVD2026-08-01
CVE-2026-14540A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-tHIGH8.010%ileNVD2026-07-31
CVE-2026-59931PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 tHIGH7.742%ileNVD2026-07-28
CVE-2026-67201V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allowsHIGH7.732%ileNVD2026-07-29
CVE-2026-67346Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url HIGH7.721%ileNVD2026-07-30
CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 acHIGH7.722%ileNVD2026-08-03
CVE-2026-18378A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able tHIGH7.615%ileNVD2026-07-30
CVE-2026-18381A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom rHIGH7.610%ileNVD2026-07-30
CVE-2026-69257Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP HIGH7.6NVD2026-08-04
CVE-2026-55391datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.510%ileNVD2026-07-28
CVE-2026-18446fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a referHIGH7.513%ileNVD2026-07-31
CVE-2024-43204Apache HTTP Server: SSRF with mod_headers setting Content-Type headerHIGH7.552%ileMicrosoft2025-07-08
CVE-2026-54660swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolHIGH7.416%ileNVD2026-07-29
CVE-2026-23904Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A reHIGH7.323%ileNVD2026-07-29
CVE-2026-69246Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text andHIGH7.212%ileNVD2026-08-03
CVE-2026-54885Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuMEDIUM6.930%ileNVD2026-07-30
CVE-2026-69198ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, evMEDIUM6.920%ileNVD2026-08-03
CVE-2026-46678Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, whenMEDIUM6.836%ileNVD2026-07-29
CVE-2026-54249Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, andMEDIUM6.810%ileNVD2026-07-29
CVE-2026-18382A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user ableMEDIUM6.820%ileNVD2026-07-30
GHSA-vg6v-j97m-h5xq@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request MEDIUM6.8GitHub2026-07-28
CVE-2026-15974SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitizeMEDIUM6.511%ileNVD2026-07-30
CVE-2026-52371A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticatMEDIUM6.513%ileNVD2026-07-31
CVE-2026-57211RabbitMQ: UNC SSRF affecting the management UI on WindowsMEDIUM6.535%ileMicrosoft2026-07-14
CVE-2026-48858ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksMEDIUM6.514%ileMicrosoft2026-06-09
CVE-2026-67530WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/MEDIUM6.45%ileNVD2026-07-30
CVE-2026-54663swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolMEDIUM6.18%ileNVD2026-07-29
CVE-2026-66325Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofinMEDIUM6.133%ileNVD2026-08-04
CVE-2026-67435linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to veMEDIUM6.021%ileNVD2026-07-29
CVE-2026-18369A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dnsMEDIUM5.89%ileNVD2026-07-30
CVE-2026-10526The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests thMEDIUM5.84%ileNVD2026-08-04
CVE-2026-18647A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue MEDIUM5.528%ileNVD2026-08-03
CVE-2026-70367A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS prMEDIUM5.4NVD2026-08-04
CVE-2026-64870MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool pMEDIUM5.312%ileNVD2026-07-30
CVE-2026-59231Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users toMEDIUM5.318%ileNVD2026-07-31
CVE-2026-18736Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serveMEDIUM5.316%ileNVD2026-08-03
CVE-2026-16536The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL befMEDIUM5.34%ileNVD2026-08-04
CVE-2026-6089The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imporMEDIUM4.920%ileNVD2026-07-29
CVE-2026-48522PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemesMEDIUM4.213%ileMicrosoft2026-05-12
CVE-2026-4912The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versioMEDIUM4.115%ileNVD2026-07-28
CVE-2026-54272ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checksMEDIUM17%ileGitHub2026-08-03
CVE-2026-53607@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host headerLOW3.713%ileGitHub2026-07-31
CVE-2026-57232Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end modLOW3.18%ileNVD2026-07-31
CVE-2026-18774A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agLOW2.1NVD2026-08-04
CVE-2026-18775A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browseLOW2.1NVD2026-08-04
CVE-2025-62718Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRFUNKNOWN64%ileMicrosoft2026-04-14
CVE-2026-8328FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addressUNKNOWN37%ileMicrosoft2026-05-12
CVE-2026-46683Snappy: SSRF and local file read via the xsl-style-sheet optionUNKNOWN16%ileMicrosoft2026-06-09
CVE-2026-50221OSSA-2026-024: Swift proxy-server SSRF via header injectionUNKNOWN4%ileOpenStack2026-06-23