VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-34504High· 8.3
6mo ago

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit ungu…

▾ Twilightopenclaw · openclawEPSS 0.39%via NVD
CVE-2026-34163High· 7.7
6mo ago

FastGPT is an AI Agent building platform

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept a user-supplied URL parameter and mak…

▾ Twilightfastgpt · fastgptEPSS 0.42%via NVD
CVE-2026-34162Critical· 10.0
6mo ago

FastGPT is an AI Agent building platform

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a …

▾ Midnightfastgpt · fastgptEPSS 0.62%via NVD
CVE-2026-5205Medium· 6.3
6mo ago

A vulnerability was identified in chatwoot up to 4.11.2

A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-34360Medium· 5.8
6mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and m…

▾ Sunlithapifhir · hl7_fhir_coreEPSS 0.32%via NVD
CVE-2026-4874Low· 3.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to…

▾ SunlitEPSS 0.33%via NVD
CVE-2025-71259Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

▾ Twilightbmc · footprintsEPSS 13%via NVD
CVE-2025-71258Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

▾ Twilightbmc · footprintsEPSS 17%via NVD
CVE-2026-29049Medium· 4.3
6mo ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…

▾ Sunlitchainguard · melangeEPSS 0.39%via NVD
CVE-2026-25580High· 8.6
7mo ago

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When …

▾ Twilightpydantic · pydantic_aiEPSS 0.67%via NVD
CVE-2026-24779High· 7.1
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …

▾ Twilightvllm · vllmEPSS 0.59%via NVD
CVE-2026-24117Medium· 5.3
8mo ago

github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) (CVE-2026-24117)

A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a p…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.37%via CSAF
CVE-2025-68616High· 7.5PoC
8mo ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal ne…

▾ Midnightkozea · weasyprintEPSS 0.71%via NVD
CVE-2026-0532High· 8.6
8mo ago

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…

▾ TwilightRed Hat · Red Hat OpenShift distributed tracing 3EPSS 0.48%via NVD
CVE-2025-65784Medium· 6.5
8mo ago

Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.

Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.

▾ Sunlithubert · hubEPSS 0.35%via NVD
CVE-2025-62088Medium· 5.4
9mo ago

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Impo…

Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Impo…

▾ SunlitEPSS 0.19%via NVD
CVE-2025-34469High· 7.5
9mo ago

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound …

▾ Twilightcowrie · cowrieEPSS 0.68%via NVD
CVE-2025-15098Medium· 6.3
9mo ago

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/heade…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-34452None
9mo ago

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the ser…

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the ser…

▾ SunlitEPSS 5.4%via NVD
CVE-2025-14116Medium· 4.7
9mo ago

A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0

A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.aencode of the file /src/models/embed.py. Performing manipulation of the argument health_url results in server-side req…

▾ SunlitEPSS 0.26%via NVD
CVE-2025-59775High· 7.5
9mo ago

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or con…

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or con…

▾ Twilightapache · http_serverEPSS 0.82%via NVD
CVE-2025-13872Critical· 9.1
9mo ago

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to …

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to …

▾ Midnightobjectplanet · opinioEPSS 0.31%via NVD
CVE-2025-27232Medium· 4.9
10mo ago

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

▾ Sunlitzabbix · frontendEPSS 0.29%via NVD
CVE-2025-13814High· 7.3
10mo ago

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The at…

▾ Twilightmogublog_project · mogublogEPSS 0.53%via NVD
CVE-2025-13809Medium· 6.3
10mo ago

A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1

A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functionality of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/Ma…

▾ Sunlitorionsec · orion-opsEPSS 0.33%via NVD
CVE-2025-13796Medium· 6.3PoC
10mo ago

A security vulnerability has been detected in deco-cx apps up to 0.120.1

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation…

▾ TwilightEPSS 0.32%via NVD
CVE-2025-13789Medium· 6.3
10mo ago

A vulnerability was found in ZenTao up to 21.7.6-8564

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remote…

▾ Sunlitzentao · zentaoEPSS 0.29%via NVD
CVE-2025-59088High· 8.6
10mo ago

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request for…

▾ TwilightEPSS 0.46%via NVD
CVE-2025-36085Medium· 5.4
11mo ago

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF)

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitat…

▾ Sunlitibm · concertEPSS 0.16%via NVD
CVE-2025-34282Critical· 9.1PoC
11mo ago

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes th…

▾ Abyssalthingsboard · thingsboardEPSS 1.8%via NVD
CWE-918 vulnerabilities (CVEs) — page 27 · VulnSea