VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

GHSA-2x35-3fw4-9jr4High
2mo ago

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

▾ Twilightn8n · n8nvia GHSA
CVE-2026-64645High
2mo ago

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

▾ Twilightnext · nextEPSS 0.41%via GHSA
GHSA-38fj-36m5-783cMedium
2mo ago

Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-65593Medium
2mo ago

n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

▾ Sunlitn8n · n8nEPSS 0.24%via GHSA
CVE-2026-65317High· 8.6PoC
2mo ago

Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…

▾ MidnightWeaviate · VerbaEPSS 0.64%via CVEORG
CVE-2026-65056High· 8.2PoC
2mo ago

mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only valida…

▾ Midnightmzxrai · mcp-webresearchEPSS 0.41%via CVEORG
CVE-2026-65057Critical· 9.3PoC
2mo ago

Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthchec…

▾ Abyssalkeephq · keepEPSS 0.43%via CVEORG
CVE-2026-65318High· 8.6PoC
2mo ago

Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…

▾ MidnightWeaviate · VerbaEPSS 0.60%via CVEORG
CVE-2026-63764High· 8.6PoC
2mo ago

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

▾ Midnightinternlm · lmdeployEPSS 0.51%via NVD
CVE-2026-15927Medium· 6.8
2mo ago

A flaw was found in Red Hat Quay's repository-level mirror configuration feature

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror h…

▾ SunlitRed Hat · quay/quay-rhel8EPSS 0.60%via NVD
CVE-2026-59765Medium· 7.5
2mo ago

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.50%via GHSA
CVE-2026-58314High· 7.7
2mo ago

Gitea: Two SSRF findings

Gitea: Two SSRF findings

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.40%via OSV
CVE-2026-23603Low· 3.1
2mo ago

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-58418Medium· 6.5
2mo ago

Gitea: SSRF via HTTP Redirect in Repository Migration

Gitea: SSRF via HTTP Redirect in Repository Migration

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58441Medium· 6.3
2mo ago

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via GHSA
CVE-2026-58442Medium· 6.5
2mo ago

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-57894High· 8.5
2mo ago

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-63769High· 7.7PoC
2mo ago

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs

Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe inter…

▾ Midnighthuginn · huginnEPSS 0.41%via NVD
CVE-2026-61835High· 7.7
2mo ago

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

▾ Twilightdirectus · directusEPSS 0.41%via GHSA
GHSA-f4gw-2p7v-4548Medium
2mo ago

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

▾ Sunlitaxios · axiosvia GHSA
CVE-2026-54562Medium· 6.5
2mo ago

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.40%via GHSA
CVE-2026-16223Medium· 6.3
2mo ago

A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1

A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16222Medium· 6.3
2mo ago

A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1

A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16196Medium· 6.3
2mo ago

A weakness has been identified in Sipeed PicoClaw up to 0.2.9

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. Th…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-16194Medium· 6.3
2mo ago

A vulnerability was determined in zhayujie CowAgent up to 2.1.1

A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forg…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-16128High· 7.3
2mo ago

A security flaw has been discovered in zevorn rt-claw up to 0.2.0

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file claw/services/swarm/swarm.c of the component http_request. Performing a manipulation results in server-side request …

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16127High· 7.3
2mo ago

A vulnerability was identified in zevorn rt-claw up to 0.2.0

A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-sid…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16125High· 7.3
2mo ago

A vulnerability was found in zevorn rt-claw up to 0.2.0

A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation of the argument url results in…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16124Medium· 6.3
2mo ago

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to s…

▾ SunlitEPSS 0.46%via NVD
CVE-2025-71398None
2mo ago

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied n…

▾ SunlitEPSS 0.33%via NVD
CWE-918 vulnerabilities (CVEs) — page 20 · VulnSea