VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-70595Medium· 4.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…

▾ Sunlitghost · ghostEPSS 0.28%via NVD
CVE-2026-70620Medium· 6.8
1mo ago

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint con…

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint con…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-53944Medium· 5.8
1mo ago

Ghost: Private IP filtering bypass to make server-side requests to internal services

Ghost: Private IP filtering bypass to make server-side requests to internal services

▾ Sunlitghost · ghostEPSS 0.33%via GHSA
CVE-2026-53945Medium· 4.0
1mo ago

Ghost: Server-side request forgery via DNS rebinding in external request handling

Ghost: Server-side request forgery via DNS rebinding in external request handling

▾ Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-53946Medium· 5.4
1mo ago

Ghost: Mobiledoc image-size fetch SSRF

Ghost: Mobiledoc image-size fetch SSRF

▾ Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-70591Medium· 4.1
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was re…

▾ Sunlitghost · ghostEPSS 0.37%via NVD
CVE-2026-70480Medium· 4.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser withou…

▾ Sunlitopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-70485High· 7.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the litera…

▾ Twilightopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-54020Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients re…

▾ Sunlitopenwebui · open_webuiEPSS 0.25%via NVD
CVE-2026-70479High· 7.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource r…

▾ Twilightopenwebui · open_webuiEPSS 0.47%via NVD
CVE-2026-69257High· 8.6
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.…

▾ Twilightflowiseai · flowiseEPSS 0.43%via NVD
CVE-2026-18736Medium· 5.0
1mo ago

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-reso…

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-reso…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-66325Medium· 6.1
1mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.39%via CVEORG
CVE-2026-69246High· 7.2
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…

▾ Twilightguzzlehttp · guzzlehttp/guzzleEPSS 0.37%via NVD
CVE-2026-69198Medium
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's ow…

▾ Sunlitip-address · ip-addressEPSS 0.48%via NVD
CVE-2026-69192High· 8.6
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, an…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.66%via NVD
CVE-2026-67311Medium· 6.8
1mo ago

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource po…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-52371Medium· 6.5
1mo ago

A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

▾ SunlitEPSS 0.40%via NVD
CVE-2026-57232Low· 3.1
1mo ago

Contao is an Open Source CMS

Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or priv…

▾ Sunlitcontao · contao/contaoEPSS 0.29%via NVD
CVE-2026-14540Medium· 6.1
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled par…

▾ Sunlitgoogle · mcp_toolbox_for_databasesEPSS 0.13%via NVD
CVE-2026-53607Low· 3.7
1mo ago

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

▾ Sunlitapostrophe · apostropheEPSS 0.32%via GHSA
CVE-2026-53500High· 8.2
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist.…

▾ Twilightthumbor · thumborEPSS 0.50%via NVD
CVE-2026-54725Critical· 9.6
1mo ago

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, M…

▾ Midnightbank-vaults · github.com/bank-vaults/vault-secrets-webhookEPSS 0.45%via NVD
CVE-2026-12075High· 8.6
1mo ago

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORC…

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

▾ Twilightnltk · nltkvia OSV
CVE-2026-54729High
1mo ago

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no addres…

▾ Twilightdssrf · dssrfEPSS 0.48%via NVD
CVE-2026-57862High· 8.5PoC
1mo ago

Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadeci…

▾ MidnightKanboard · KanboardEPSS 0.41%via CVEORG
CVE-2026-66415High· 8.5
1mo ago

Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import()

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blue…

▾ TwilightLeantime · LeantimeEPSS 0.35%via CVEORG
CVE-2026-18369Medium· 5.8
1mo ago

Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated AC…

▾ SunlitRed Hat · redhat-pki:10EPSS 0.22%via CVEORG
CVE-2026-18378High· 7.6
1mo ago

A flaw was found in koku-metrics-operator

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-67435Medium
1mo ago

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.50%via GHSA
CWE-918 vulnerabilities (CVEs) — page 18 · VulnSea