VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-13540Medium· 6.3
3mo ago

A security flaw has been discovered in GitBucket up to 4.46.1

A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argum…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-49869Critical· 10.0CISA KEVPoC
3mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

▾ Hadalkestra · kestraEPSS 2.1%via NVD
CVE-2026-48782Medium· 6.8
3mo ago

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)

▾ Sunlitpydantic-ai-slim · pydantic-ai-slimEPSS 0.42%via GHSA
GHSA-vgrc-hq28-p3xpHigh· 7.4
3mo ago

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

▾ Twilightapernet · github.com/apernet/hysteria/core/v2via GHSA
GHSA-rp72-5v5q-2446Low
3mo ago

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

▾ Sunlitcardano402 · @cardano402/mcp-servervia GHSA
CVE-2026-47076Medium
3mo ago

Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host

Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host

▾ Sunlithackney · hackneyEPSS 0.16%via GHSA
CVE-2026-49359Medium· 6.5
3mo ago

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.42%via GHSA
CVE-2026-54242Medium· 4.9
3mo ago

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

▾ Sunlitstatamic · statamic/cmsEPSS 0.23%via GHSA
CVE-2026-44161High· 7.2
3mo ago

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

▾ Twilightfluentd · fluentdEPSS 0.44%via GHSA
CVE-2026-12992High· 7.4
3mo ago

A flaw was found in Apicurio Registry

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload …

▾ Twilightredhat · build_of_apicurio_registryEPSS 0.34%via NVD
CVE-2026-57303High· 7.1
3mo ago

Jenkins Assembla Plugin has an XXE vulnerability

Jenkins Assembla Plugin has an XXE vulnerability

▾ Twilightjenkins-ci · org.jenkins-ci.plugins:assemblaEPSS 0.36%via GHSA
CVE-2026-50221Medium· 5.4
3mo ago

OpenStack Swift vulnerable to authenticated server-side request forgery

OpenStack Swift vulnerable to authenticated server-side request forgery

▾ Sunlitswift · swiftEPSS 0.22%via OSV
GHSA-w4hm-rrxg-pxcfMedium· 7.1
3mo ago

Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability

Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability

▾ Sunlitflowise · flowisevia GHSA
CVE-2026-54514Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)

A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
CVE-2026-21887High· 7.7
3mo ago

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

▾ Twilightpycti · pyctiEPSS 0.21%via GHSA
CVE-2026-44583Medium· 5.3
3mo ago

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.41%via GHSA
CVE-2026-47267Medium
3mo ago

Gogs has SSRF in webhook deliveries

Gogs has SSRF in webhook deliveries

▾ Sunlitgogs · gogs.io/gogsEPSS 0.42%via GHSA
CVE-2026-48153High· 8.5
3mo ago

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

▾ Twilightbudibase · @budibase/serverEPSS 0.29%via GHSA
CVE-2026-54353High· 8.5
3mo ago

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

▾ Twilightbudibase · @budibase/backend-coreEPSS 0.21%via GHSA
CVE-2026-12798Medium· 6.3
3mo ago

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-55414Medium· 5.3
3mo ago

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

▾ Sunlitnl-portal · nl.nl-portal:formvia GHSA
GHSA-r46f-3rpw-hxrvHigh
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

▾ Twilightgohugoio · github.com/gohugoio/hugovia GHSA
CVE-2026-55187Medium· 5.8
3mo ago

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.38%via GHSA
GHSA-mrvx-jmjw-vggcHigh· 7.1
3mo ago

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

▾ Twilightmcp-searxng · mcp-searxngvia GHSA
GHSA-4cc2-g9w2-fhf6Medium· 5.9
3mo ago

Zeep: Server-Side Request Forgery (SSRF)

Zeep: Server-Side Request Forgery (SSRF)

▾ Sunlitzeep · zeepvia GHSA
GHSA-g2gw-q38m-vjfcHigh
3mo ago

Lokka: Azure Resource Manager URL path validation issue

Lokka: Azure Resource Manager URL path validation issue

▾ Twilightmerill · @merill/lokkavia GHSA
GHSA-h5rg-8p7f-47g2Medium· 4.1
3mo ago

SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch

SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-55671Low
3mo ago

ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components

ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.41%via GHSA
CVE-2026-55229High· 7.5PoC
3mo ago

Gotenberg: SSRF via LibreOffice document processing

Gotenberg: SSRF via LibreOffice document processing

▾ Midnightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.5%via GHSA
GHSA-6h9p-93hq-q7h6Medium· 6.5
3mo ago

PraisonAI: SpiderTools redirect-target SSRF protection bypass

PraisonAI: SpiderTools redirect-target SSRF protection bypass

▾ Sunlitpraisonaiagents · praisonaiagentsvia GHSA
CWE-918 vulnerabilities (CVEs) — page 23 · VulnSea