Weaknesses of type CWE-918

3,105 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-66844CRITICALIn grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig anEPSS 0.3%CVE-2025-27232MEDIUMFrontend arbitrary file read in oauth.authorize actionEPSS 0.3%CVE-2026-55166CRITICALLemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOREPSS 0.3%CVE-2026-76347MEDIUMServer-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure GatewayEPSS 0.3%CVE-2025-32487MEDIUMWordPress Waymark plugin <= 1.5.2 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.3%CVE-2026-19301MEDIUMLangflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple componentsEPSS 0.3%CVE-2024-33634MEDIUMWordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2025-1662MEDIUMURL Media Uploader <= 1.0.0 - Authenticated (Author+) Server-Side Request Forgery via DNS RebindingEPSS 0.3%CVE-2024-37260HIGHWordPress Foxiz Theme theme <= 2.3.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-44430MEDIUMMCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlistEPSS 0.3%CVE-2026-3048MEDIUMNexus Repository 3 - Improper LDAP Referral HandlingEPSS 0.3%CVE-2025-9799LOWLangfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgeryEPSS 0.3%CVE-2025-13378MEDIUMAI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' ParameterEPSS 0.3%CVE-2026-84301MEDIUMFastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requestsEPSS 0.3%CVE-2025-10096MEDIUMSimStudioAI sim route.ts server-side request forgeryEPSS 0.3%CVE-2024-13697MEDIUMBetter Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_linksEPSS 0.3%CVE-2024-37098MEDIUMWordPress BlossomThemes Email Newsletter plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2024-43379LOWTruffleHog has a Blind SSRF in some DetectorsEPSS 0.3%CVE-2024-11836HIGHServer-side Request ForgeryEPSS 0.3%CVE-2026-22245HIGHMastodon has SSRF Protection bypassEPSS 0.3%