CWE-918
CVEs classified under CWE-918, newest first.
840 CVEsRSS
CVE-2026-67426Critical· 9.3Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
CVE-2026-67428High· 8.5Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
CVE-2026-67424High· 8.5Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
CVE-2026-54735Critical· 10.0prebid-server's request forgery vulnerability allows for possible host environment data extraction
prebid-server's request forgery vulnerability allows for possible host environment data extraction
CVE-2026-52840Low· 2.7Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-54663Medium· 6.1swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-54690High· 8.2datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
CVE-2026-55391High· 7.5datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
CVE-2026-54691High· 8.2datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
CVE-2026-54605High· 7.2OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…
GHSA-vg6v-j97m-h5xqMedium· 6.8@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
CVE-2026-43910High· 8.2java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
CVE-2026-16481Medium· 6.0Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page Tool
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an …
CVE-2026-54272High· 7.2ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…
CVE-2026-17458Medium· 6.3A vulnerability was found in mf-yang openclaw-cn up to 0.2.1
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server…
CVE-2026-57106Critical· 10.0Data Quality Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
GHSA-8q49-2h5h-434xMedium· 5.9FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-v42f-v8xc-j435High· 8.5Budibase: SSRF via DNS rebinding in the REST datasource integration
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-hfhx-w8p8-4hc7MediumBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-v6w6-358x-2433Medium· 5.4Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
CVE-2026-59221High· 7.7open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
GHSA-xg5g-26x8-cvf4High· 8.5Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
CVE-2026-59867High· 7.1Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-59863HighMicrosoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
CVE-2026-56167High· 8.5Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVE-2026-59931High· 7.7PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
CVE-2026-64649HighNext.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-vhf8-cg2h-cg3pMediumn8n: SSRF Protection Bypass via MCP Client Node
n8n: SSRF Protection Bypass via MCP Client Node