CWE-918
CVEs classified under CWE-918, newest first.
840 CVEsRSS
CVE-2026-13540Medium· 6.3A security flaw has been discovered in GitBucket up to 4.46.1
A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argum…
CVE-2026-49869Critical· 10.0CISA KEVPoCKestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…
CVE-2026-48782Medium· 6.8pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
GHSA-vgrc-hq28-p3xpHigh· 7.4Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
GHSA-rp72-5v5q-2446Low@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
CVE-2026-47076MediumHackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host
Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host
CVE-2026-49359Medium· 6.5PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
CVE-2026-54242Medium· 4.9Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-44161High· 7.2Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
CVE-2026-12992High· 7.4A flaw was found in Apicurio Registry
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload …
CVE-2026-57303High· 7.1Jenkins Assembla Plugin has an XXE vulnerability
Jenkins Assembla Plugin has an XXE vulnerability
CVE-2026-50221Medium· 5.4OpenStack Swift vulnerable to authenticated server-side request forgery
OpenStack Swift vulnerable to authenticated server-side request forgery
GHSA-w4hm-rrxg-pxcfMedium· 7.1Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability
Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability
CVE-2026-54514Medium· 5.3jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)
A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…
CVE-2026-21887High· 7.7OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
CVE-2026-44583Medium· 5.3Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
CVE-2026-47267MediumGogs has SSRF in webhook deliveries
Gogs has SSRF in webhook deliveries
CVE-2026-48153High· 8.5Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
CVE-2026-54353High· 8.5@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
CVE-2026-12798Medium· 6.3BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-55414Medium· 5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
GHSA-r46f-3rpw-hxrvHighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-55187Medium· 5.8Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
GHSA-mrvx-jmjw-vggcHigh· 7.1SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
GHSA-4cc2-g9w2-fhf6Medium· 5.9Zeep: Server-Side Request Forgery (SSRF)
Zeep: Server-Side Request Forgery (SSRF)
GHSA-g2gw-q38m-vjfcHighLokka: Azure Resource Manager URL path validation issue
Lokka: Azure Resource Manager URL path validation issue
GHSA-h5rg-8p7f-47g2Medium· 4.1SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
CVE-2026-55671LowZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
CVE-2026-55229High· 7.5PoCGotenberg: SSRF via LibreOffice document processing
Gotenberg: SSRF via LibreOffice document processing
GHSA-6h9p-93hq-q7h6Medium· 6.5PraisonAI: SpiderTools redirect-target SSRF protection bypass
PraisonAI: SpiderTools redirect-target SSRF protection bypass