VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-85179High· 8.5PoC
3w ago

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private…

▾ MidnightHumanSignal · label-studioEPSS 0.40%via NVD
CVE-2026-85164High· 7.1
3w ago

WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them

WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-85106Medium· 6.3
3w ago

A vulnerability has been found in NousResearch hermes-agent 0.18.0

A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url le…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-84697Medium· 5.3
3w ago

Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations

Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply ho…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-84377Medium· 6.5
3w ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls a…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.54%via NVD
CVE-2026-55421Medium· 6.8
3w ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allow_redirects=True)". …

▾ SunlitEPSS 0.46%via NVD
CVE-2026-73474Medium· 5.3
3w ago

Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery

Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.

▾ Sunlitentity_share_websub_project · entity_share_websubEPSS 0.34%via NVD
CVE-2026-18730High· 7.4
3w ago

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthent…

▾ Twilightgithub · enterprise_serverEPSS 0.29%via NVD
CVE-2026-8712High· 8.3
3w ago

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the…

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-84207Medium· 5.4
3w ago

Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services

Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-76851High· 8.8
3w ago

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an in…

▾ Twilightgithub · enterprise_serverEPSS 0.83%via NVD
CVE-2026-84196High· 7.7
3w ago

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers…

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.35%via NVD
CVE-2026-84199High· 7.7
3w ago

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions …

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.36%via NVD
CVE-2025-15613Medium· 6.5
3w ago

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify an external URL in a policy's apiCall/service conf…

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.27%via NVD
CVE-2026-82866Medium· 6.8
3w ago

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-82659High· 7.1
3w ago

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.35%via NVD
CVE-2026-53507None
3w ago

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the OpenAPI spec by default (allow-external-r…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-77352Medium· 4.3
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to i…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-77351Low· 3.5
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-77348High· 8.2
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-61640None
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero S…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-61638None
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer …

▾ SunlitEPSS 0.50%via NVD
CVE-2026-79749None
3w ago

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, MCPHub's SSRF guard in src/utils/ssrf.ts uses a cus…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-79747High· 7.1
3w ago

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authenticated non-admin user can register a serv…

▾ TwilightEPSS 0.30%via NVD
CVE-2026-62993Medium· 8.6
3w ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and…

▾ Sunlitsmarty · smarty/smartyEPSS 0.57%via NVD
CVE-2026-81889High· 8.6
3w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable becau…

▾ Twilightstudio-42 · studio-42/elfinderEPSS 0.55%via NVD
CVE-2026-53508Medium
3w ago

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRef…

▾ Sunlitoasdiff · github.com/oasdiff/oasdiffEPSS 0.50%via NVD
CVE-2026-82556Medium· 6.3
4w ago

A vulnerability was found in Forgejo up to 15.0.4

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation resu…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.37%via NVD
CVE-2026-82638High· 7.5PoC
4w ago

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresse…

▾ Midnightjina-ai · readerEPSS 0.50%via NVD
CVE-2026-82476Medium· 5.3
4w ago

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal ho…

▾ SunlitEPSS 0.43%via NVD
CWE-918 vulnerabilities (CVEs) — page 11 · VulnSea