VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-16084High· 7.3
2mo ago

A weakness has been identified in Sipeed PicoClaw up to 0.2.9

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools/integration/web.go. This manipulation causes server-side request forgery. Remote exploitation of the attack is possi…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-55177High
2mo ago

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

▾ Twilighttak-ps · @tak-ps/cloudtakvia GHSA
CVE-2026-50552Medium· 6.3
2mo ago

Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail

Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail

▾ Sunlitphanan · phanan/koelEPSS 0.27%via GHSA
GHSA-8q6q-m837-fv64Medium· 6.4
2mo ago

Koel has SSRF through Authenticated Subsonic podcast feed URLs

Koel has SSRF through Authenticated Subsonic podcast feed URLs

▾ Sunlitphanan · phanan/koelvia GHSA
CVE-2026-7494Medium· 5.0
2mo ago

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to interna…

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.17%via NVD
CVE-2026-14645Medium· 5.5
2mo ago

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to sen…

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to sen…

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.26%via NVD
CVE-2026-14646High· 7.7
2mo ago

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-co…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.26%via NVD
CVE-2026-55051Medium· 6.5
2mo ago

Microsoft SharePoint Server Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.91%via CVEORG
CVE-2026-48259Critical· 9.6
2mo ago

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to i…

▾ Midnightadobe · experience_managerEPSS 0.90%via NVD
GHSA-7rx3-5wx3-5v76High· 7.7
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

▾ Twilightforgekeep · github.com/forgekeep/nebula-meshvia GHSA
CVE-2026-50131High· 8.6PoC
2mo ago

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

▾ Midnightfedify · @fedify/fedifyEPSS 0.42%via GHSA
CVE-2026-45262Critical· 9.9
2mo ago

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-62240High· 7.4PoC
2mo ago

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the secur…

▾ Midnightcrewai · crewaiEPSS 0.52%via NVD
CVE-2026-55372High· 7.2
2mo ago

NukeViet: Pre-authentication SSRF via X-Forwarded-Host

NukeViet: Pre-authentication SSRF via X-Forwarded-Host

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-62143None
2mo ago

A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges

A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. H…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-15525Medium· 6.3
2mo ago

A vulnerability was detected in kLOsk adloop up to 0.9.0

A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the argument final_url results in server-side request forg…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-15508Medium· 6.3
2mo ago

A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30

A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. Executing a manipulation of the argument…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15501Medium· 6.3
2mo ago

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function ToolsRoute.test_mcp_connection of the file astrbot/dashboard/routes/tools.py of the component MCP Test Endpoint. The m…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15500Medium· 6.3
2mo ago

A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2

A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this vulnerability is the function get_online_plugins of the file astrbot/dashboard/routes/plugin.py of the component market_list Endpoint. Executing a manip…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-61429High· 8.5
2mo ago

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URL…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-15378Critical· 9.3
2mo ago

A flaw was found in the `guardrails-detectors` component

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can le…

▾ MidnightRed Hat · rhoai/odh-fms-guardrails-orchestrator-rhel9EPSS 0.53%via NVD
CVE-2026-55807None
2mo ago

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-49213High· 8.1
2mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because validateIPAddress blocks local, metadata, and…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-13233NonePoC
2mo ago

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.

▾ TwilightEPSS 0.21%via NVD
CVE-2026-57575None
2mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions bef…

▾ SunlitEPSS 0.60%via NVD
CVE-2026-57211Medium· 6.5
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path v…

▾ SunlitEPSS 0.63%via NVD
CVE-2026-53450High· 7.4
2mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mappe…

▾ TwilightEPSS 0.29%via NVD
CVE-2026-55641High· 8.2
2mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypas…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-15330High· 7.3
2mo ago

A vulnerability was determined in zhayujie CowAgent up to 2.1.1

A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the a…

▾ TwilightEPSS 0.60%via NVD
GHSA-489g-7rxv-6c8qMedium· 6.5
2mo ago

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

▾ Sunlitmcp-atlassian · mcp-atlassianvia OSV
CWE-918 vulnerabilities (CVEs) — page 21 · VulnSea