Weaknesses of type CWE-918

3,106 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-59552HIGHWordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-59278MEDIUMIn Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packagesEPSS 0.3%CVE-2026-66704HIGHWordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-57348HIGHWordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-44428LOWMCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audienceEPSS 0.3%CVE-2026-55537HIGHPraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114EPSS 0.3%CVE-2025-46651MEDIUMTiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient valEPSS 0.3%CVE-2026-41689MEDIUMWallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal servicesEPSS 0.3%CVE-2026-79659HIGHEch0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfoEPSS 0.3%CVE-2026-14646MEDIUMNexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP RedirectEPSS 0.3%CVE-2024-13834MEDIUMResponsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme <= 3.1.4 - Authenticated (Contributor+) Blind Server-Side Request Forgery via remote_requestEPSS 0.3%CVE-2026-10586HIGHGutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request ForgeryEPSS 0.3%CVE-2026-48051LOWPapra: SSRF via HTTP redirect bypass in webhook deliveryEPSS 0.3%CVE-2026-85614CRITICALOpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkerEPSS 0.3%CVE-2026-81549CRITICALDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.3%CVE-2026-2274HIGHArbitrary File Read and SSRF in Google AppSheetEPSS 0.3%CVE-2025-45939MEDIUMApwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function.EPSS 0.3%CVE-2026-100373MEDIUMOpenMetadata through 2.0.2 SSRF via Webhook URL Validation BypassEPSS 0.3%CVE-2024-41737MEDIUMServer-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)EPSS 0.3%CVE-2026-24902HIGHTrustTunnel has SSRF and private network restriction bypass via numeric address destinationsEPSS 0.3%