VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

838 CVEsRSS

GHSA-9qhg-99ww-9mqcHigh· 8.2
1mo ago

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

▾ Twilightutcp-http · utcp-httpvia GHSA
GHSA-ppx3-28rw-8fpfMedium· 4.7
1mo ago

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

▾ Sunlitutcp-gql · utcp-gqlvia GHSA
GHSA-8cp3-qxj6-px34High· 7.1
1mo ago

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

▾ Twilightutcp-http · utcp-httpvia GHSA
CVE-2026-55526High· 8.5
1mo ago

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.36%via OSV
CVE-2026-55537High· 7.1
1mo ago

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

▾ Twilightpraisonai · praisonaiEPSS 0.27%via OSV
CVE-2026-55535Medium· 6.8
1mo ago

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

▾ Sunlitpraisonai · praisonaiEPSS 0.34%via OSV
CVE-2026-55525High· 7.5
1mo ago

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.51%via OSV
CVE-2026-10582High· 7.4
1mo ago

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.32%via NVD
CVE-2026-78205Medium· 5.8
1mo ago

BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, CGNAT)

BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, CGNAT). In versions 1.4.19 …

▾ SunlitEPSS 0.41%via NVD
CVE-2026-77310Medium· 5.3
1mo ago

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress br…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-76838High· 8.5
1mo ago

Hi.Events validates a webhook destination only when it is registered, never when it is used

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reser…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-75899High· 7.5
1mo ago

fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)

A flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-75975High· 7.5
1mo ago

fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)

A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a mal…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-63311Medium· 5.3
1mo ago

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during s…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-78003Critical· 9.8
1mo ago

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which a…

▾ MidnightEPSS 0.79%via NVD
CVE-2026-22681High· 8.5
1mo ago

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can …

▾ TwilightEPSS 0.34%via NVD
CVE-2026-77775High· 8.6
1mo ago

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-69502Critical· 10.0
1mo ago

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_sql_databaseEPSS 0.80%via NVD
CVE-2026-63004Medium· 5.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Team…

▾ Sunlitunleash-server · unleash-serverEPSS 0.39%via NVD
CVE-2026-54457High· 7.7
1mo ago

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied…

▾ Twilighttensorzero · tensorzeroEPSS 0.40%via NVD
CVE-2026-53509Medium· 5.7
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to a…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-47735High
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The …

▾ Twilightbasekick-labs · github.com/basekick-labs/arcEPSS 0.43%via NVD
CVE-2026-72848High· 8.6PoC
1mo ago

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over …

▾ Midnightlangchain-ai · langchain-communityEPSS 0.60%via NVD
CVE-2026-72846Medium· 6.4PoC
1mo ago

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsCl…

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsCl…

▾ Twilightlightdash · lightdashEPSS 0.32%via NVD
CVE-2026-77066Medium· 5.0PoC
1mo ago

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(…

▾ Twilightomnivore-app · omnivoreEPSS 0.25%via NVD
CVE-2026-77067Medium· 5.0PoC
1mo ago

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/s…

▾ Twilightomnivore-app · omnivoreEPSS 0.27%via NVD
CVE-2026-54508None
1mo ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsUrl() in…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-72860High· 8.5PoC
1mo ago

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares host…

▾ Midnightdecolua · 9routerEPSS 0.38%via NVD
CVE-2026-77648Low· 2.2
1mo ago

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is use…

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is use…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-77646None
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

▾ SunlitEPSS 0.44%via NVD
CWE-918 vulnerabilities (CVEs) — page 13 · VulnSea