Weaknesses of type CWE-918

3,100 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-62197MEDIUMOpenClaw < 2026.6.6 Policy Bypass via CDP DiscoveryEPSS 0.3%CVE-2026-63311MEDIUMNLTK before 3.10.0 SSRF via DNS Resolution FailureEPSS 0.3%CVE-2026-82243HIGHBudibase Server before 3.41.3 SSRF with Credential LeakageEPSS 0.3%CVE-2026-77249MEDIUMMCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookupEPSS 0.3%CVE-2017-20106MEDIUMLithium Forum Compose Message server-side request forgeryEPSS 0.3%CVE-2019-25251MEDIUMTeradek VidiU Pro 3.0.3 Server-Side Request Forgery via RTMP SettingsEPSS 0.3%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2025-9269MEDIUMServer-Side Request Forgery (SSRF) vulnerability found in embedded web serverEPSS 0.3%CVE-2025-45475MEDIUMmaccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.EPSS 0.3%CVE-2025-8341MEDIUMSSRF in Infinity Datasource PluginEPSS 0.3%CVE-2026-41270HIGHFlowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxEPSS 0.3%CVE-2019-25451MEDIUMphpMoAdmin 1.1.5 Cross-Site Request Forgery via moadmin.phpEPSS 0.3%CVE-2026-25528MEDIUMLangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header InjectionEPSS 0.3%CVE-2025-70042CRITICALAn issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.EPSS 0.3%CVE-2025-8020HIGHAll versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname EPSS 0.3%CVE-2026-41687MEDIUMWallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline ChecksEPSS 0.3%CVE-2026-47879HIGHSpring Cloud Gateway SSRF and native file access with gRPCEPSS 0.3%CVE-2026-11370MEDIUMWP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' ParameterEPSS 0.3%CVE-2026-25738MEDIUMIndico has Server-Side Request Forgery (SSRF) in multiple placesEPSS 0.3%CVE-2026-43936MEDIUMe107: Server-Side Request Forgery (SSRF) in the remote file fetcherEPSS 0.3%