CWE-918: SSRF
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
2,530 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-15409 — A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
- CVE-2026-64849 — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
- CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
- CVE-2024-32964 — lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
- CVE-2026-44578 — Next.js: Server-side request forgery in applications using WebSocket upgrades
- CVE-2024-20404 — A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
- CVE-2026-49869 — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
- CVE-2026-83548 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
- CVE-2024-47008 — Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak se
- CVE-2026-54157 — LobeHub: Unauthenticated SSRF in `/webapi/proxy`
- CVE-2026-34162 — FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft
- CVE-2026-22039 — Kyverno Cross-Namespace Privilege Escalation via Policy apiCall
- CVE-2025-64180 — Manager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)
- CVE-2025-54122 — Manager-io/Manager allows unauthenticated full read server-side request forgery in "proxy" endpoint
- CVE-2025-54381 — BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
- CVE-2024-0455 — SSRF on AWS deployed instances of AnythingLLM via /metadata
- CVE-2024-48874 — Ruijie Reyee OS Server-Side Request Forgery
- CVE-2026-66842 — BIG-IP and BIG-IQ Configuration utility vulnerability
- CVE-2026-31818 — Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
- CVE-2025-64709 — Typebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook Block
Recently published
- CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
- CVE-2026-87821 — Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch
- CVE-2026-79635 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-57866 — Apache Impala: Secrets Exfiltration via SSRF
- CVE-2026-54048 — Apache Impala: Avro Schema URL Server-Side Request Forgery
- CVE-2026-19733 — SSRF in Yordam Informatics's Library Automation System
- CVE-2026-80123 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87084 — Tanium addressed a server-side request forgery vulnerability in Enforce.
- CVE-2026-87595 — Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging socia
- CVE-2026-86082 — n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
- CVE-2026-86806 — opengeos GeoLibre _is_within_roots server-side request forgery
- CVE-2026-86074 — n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
- CVE-2026-48707 — InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning
- CVE-2026-86735 — snipe-it before 8.7.0 SSRF via IPv6 transition address bypass
- CVE-2026-73315 — XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler
- CVE-2026-86590 — In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passe
- CVE-2026-81806 — WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerability
- CVE-2026-76971 — Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence
- CVE-2026-86539 — knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
- CVE-2026-82757 — ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF