CWE-918
CVEs classified under CWE-918, newest first.
840 CVEsRSS
GHSA-2x35-3fw4-9jr4Highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
CVE-2026-64645HighNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
GHSA-38fj-36m5-783cMediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65317High· 8.6PoCVerba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…
CVE-2026-65056High· 8.2PoCmcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only valida…
CVE-2026-65057Critical· 9.3PoCKeep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthchec…
CVE-2026-65318High· 8.6PoCVerba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…
CVE-2026-63764High· 8.6PoCLMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
CVE-2026-15927Medium· 6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror h…
CVE-2026-59765Medium· 7.5Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
Gitea: Two SSRF findings
CVE-2026-23603Low· 3.1Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-58418Medium· 6.5Gitea: SSRF via HTTP Redirect in Repository Migration
Gitea: SSRF via HTTP Redirect in Repository Migration
CVE-2026-58441Medium· 6.3Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58442Medium· 6.5Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-57894High· 8.5Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-63769High· 7.7PoCHuginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs
Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe inter…
CVE-2026-61835High· 7.7Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
GHSA-f4gw-2p7v-4548MediumAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
CVE-2026-54562Medium· 6.5Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
CVE-2026-16223Medium· 6.3A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1
A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit …
CVE-2026-16222Medium· 6.3A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1
A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint…
CVE-2026-16196Medium· 6.3A weakness has been identified in Sipeed PicoClaw up to 0.2.9
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. Th…
CVE-2026-16194Medium· 6.3A vulnerability was determined in zhayujie CowAgent up to 2.1.1
A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forg…
CVE-2026-16128High· 7.3A security flaw has been discovered in zevorn rt-claw up to 0.2.0
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file claw/services/swarm/swarm.c of the component http_request. Performing a manipulation results in server-side request …
CVE-2026-16127High· 7.3A vulnerability was identified in zevorn rt-claw up to 0.2.0
A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-sid…
CVE-2026-16125High· 7.3A vulnerability was found in zevorn rt-claw up to 0.2.0
A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation of the argument url results in…
CVE-2026-16124Medium· 6.3A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to s…
CVE-2025-71398NoneSurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses
SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied n…