VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

CVE-2026-82477Medium· 5.8
4w ago

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.

▾ SunlitEPSS 0.47%via NVD
CVE-2026-77012Critical· 9.3
4w ago

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing una…

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing una…

▾ MidnightEPSS 0.35%via NVD
CVE-2026-16947Critical· 9.1
4w ago

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, all…

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, all…

▾ MidnightEPSS 0.24%via NVD
CVE-2026-16600High· 7.7
4w ago

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and abov…

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and abov…

▾ TwilightEPSS 0.19%via NVD
CVE-2026-82270High· 7.5
1mo ago

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward …

▾ TwilightPortkey-AI · @portkey-ai/gatewayEPSS 0.48%via NVD
CVE-2026-82285High· 8.2PoC
1mo ago

BISHENG Unauthenticated Server-Side Request Forgery via Workflow Report Callback

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated att…

▾ Midnightdataelement · bishengEPSS 0.54%via CVEORG
CVE-2026-82289High· 7.4PoC
1mo ago

Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github

Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled host…

▾ Midnightcoderamp-labs · gitingestEPSS 0.31%via NVD
CVE-2026-82268High· 7.5PoC
1mo ago

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated …

▾ MidnightQwenLM · qwen-agentEPSS 0.35%via NVD
CVE-2026-54745Critical· 10.0
1mo ago

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy…

▾ MidnightEPSS 0.62%via NVD
CVE-2026-82081Medium· 6.4
1mo ago

wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-82263Medium· 6.8PoC
1mo ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbit…

▾ Twilightlogto-io · logtoEPSS 0.46%via NVD
CVE-2026-82262Medium· 6.8
1mo ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server …

▾ Sunlitlogto-io · logtoEPSS 0.46%via NVD
CVE-2026-55245High
1mo ago

Bifrost is an enterprise AI gateway for routing requests to model providers

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, clas…

▾ Twilightmaximhq · github.com/maximhq/bifrost/coreEPSS 0.61%via NVD
CVE-2026-81093High· 8.6
1mo ago

The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax

The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from src/utils/generic.ts, which confirmed t…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-81091High· 8.6
1mo ago

The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names

The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the _…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-47879High· 7.7
1mo ago

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Sp…

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Sp…

▾ Twilightvmware · spring_cloud_gatewayEPSS 0.33%via NVD
CVE-2026-55758None
1mo ago

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, the SSRF protection in projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java b…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-81678High· 7.5
1mo ago

AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats

AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers c…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-80347High· 7.5
1mo ago

mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal

mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, …

▾ TwilightEPSS 0.35%via NVD
CVE-2026-80350High· 7.1
1mo ago

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTarge…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-77573Low· 3.5
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal serv…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-75340Critical· 9.1
1mo ago

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

▾ MidnightEPSS 0.40%via NVD
CVE-2026-52776High
1mo ago

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.44%via NVD
CVE-2026-79788High· 7.1
1mo ago

In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied

In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a resul…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-34964Medium· 5.8
1mo ago

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can in…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-78682High· 7.5
1mo ago

nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)

A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via CSAF
CVE-2026-76193Critical· 10.0
1mo ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbi…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-79659High· 7.7
1mo ago

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbit…

▾ Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.26%via NVD
CVE-2026-45019High· 7.2
1mo ago

Chainlit is a Python framework for building production-ready conversational AI applications

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…

▾ Twilightchainlit · chainlitEPSS 0.43%via NVD
CVE-2026-12210Medium· 4.7
1mo ago

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

▾ Sunlitutcp-gql · utcp-gqlEPSS 0.23%via OSV
CWE-918 vulnerabilities (CVEs) — page 12 · VulnSea