VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-67426Critical· 9.3
1mo ago

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

▾ Midnightflyto-core · flyto-coreEPSS 0.51%via GHSA
CVE-2026-67428High· 8.5
1mo ago

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

▾ Twilightflyto-core · flyto-coreEPSS 0.45%via GHSA
CVE-2026-67424High· 8.5
1mo ago

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

▾ Twilightflyto-core · flyto-coreEPSS 0.41%via GHSA
CVE-2026-54735Critical· 10.0
2mo ago

prebid-server's request forgery vulnerability allows for possible host environment data extraction

prebid-server's request forgery vulnerability allows for possible host environment data extraction

▾ Midnightprebid · github.com/prebid/prebid-server/v4EPSS 0.61%via GHSA
CVE-2026-52840Low· 2.7
2mo ago

Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.31%via GHSA
CVE-2026-54660High· 7.4
2mo ago

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.44%via GHSA
CVE-2026-54663Medium· 6.1
2mo ago

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

▾ Sunlitswagger-typescript-api · swagger-typescript-apiEPSS 0.32%via GHSA
CVE-2026-54690High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.39%via OSV
CVE-2026-55391High· 7.5
2mo ago

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.30%via OSV
CVE-2026-54691High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.38%via OSV
CVE-2026-54605High· 7.2
2mo ago

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…

▾ Twilightoauth · oauthEPSS 0.19%via NVD
GHSA-vg6v-j97m-h5xqMedium· 6.8
2mo ago

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

▾ Sunlitnovu · @novu/application-genericvia GHSA
CVE-2026-43910High· 8.2
2mo ago

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

▾ Twilightappium · io.appium:java-clientEPSS 0.43%via GHSA
CVE-2026-16481Medium· 6.0
2mo ago

Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page Tool

A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an …

▾ SunlitGoogle · MCP Toolbox for Databases (googleapis/mcp-toolbox)EPSS 0.22%via CVEORG
CVE-2026-54272High· 7.2
2mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.43%via NVD
CVE-2026-17458Medium· 6.3
2mo ago

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-57106Critical· 10.0
2mo ago

Data Quality Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Purview Data GovernanceEPSS 0.90%via CVEORG
GHSA-8q49-2h5h-434xMedium· 5.9
2mo ago

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

▾ Sunlitfrontmcp · @frontmcp/adaptersvia GHSA
GHSA-v42f-v8xc-j435High· 8.5
2mo ago

Budibase: SSRF via DNS rebinding in the REST datasource integration

Budibase: SSRF via DNS rebinding in the REST datasource integration

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hfhx-w8p8-4hc7Medium
2mo ago

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-68r5-9hpg-7qw9Critical· 9.4
2mo ago

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-dsml-servletvia GHSA
GHSA-v6w6-358x-2433Medium· 5.4
2mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
CVE-2026-59221High· 7.7
2mo ago

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

▾ Twilightopen-webui · open-webuiEPSS 0.48%via GHSA
GHSA-xg5g-26x8-cvf4High· 8.5
2mo ago

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

▾ Twilightbudibase · @budibase/servervia GHSA
CVE-2026-59867High· 7.1
2mo ago

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 2.4%via GHSA
CVE-2026-59863High
2mo ago

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-56167High· 8.5
2mo ago

Azure AI Search Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure AI SearchEPSS 0.55%via CVEORG
CVE-2026-59931High· 7.7
2mo ago

PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.53%via GHSA
CVE-2026-64649High
2mo ago

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Next.js: Server-Side Request Forgery in Server Actions on custom servers

▾ Twilightnext · nextEPSS 0.46%via GHSA
GHSA-vhf8-cg2h-cg3pMedium
2mo ago

n8n: SSRF Protection Bypass via MCP Client Node

n8n: SSRF Protection Bypass via MCP Client Node

▾ Sunlitn8n · n8nvia GHSA
CWE-918 vulnerabilities (CVEs) — page 19 · VulnSea