Weaknesses of type CWE-918

3,106 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-13393MEDIUMFeatured Image from URL (FIFU) <= 5.3.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'fifu_input_url'EPSS 0.3%CVE-2026-54020MEDIUMOpen WebUI: DNS Rebinding SSRF BypassEPSS 0.3%CVE-2025-30997MEDIUMWordPress Car Repair Services theme <= 5.0 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.3%CVE-2026-77066MEDIUMOmnivore Server-Side Request Forgery via the scanFeeds GraphQL QueryEPSS 0.3%CVE-2024-38723MEDIUMWordPress Get Use APIs – JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-76971MEDIUMServer-Side Request Forgery in SAP Manufacturing Integration and IntelligenceEPSS 0.3%CVE-2026-10107HIGHMoviePilot v2 SSRF via /api/v1/system/img/{proxy} EndpointEPSS 0.3%CVE-2026-47268MEDIUMNezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard hostEPSS 0.3%CVE-2026-7890LOWConcrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer BlockEPSS 0.2%CVE-2025-47484MEDIUMWordPress Display Remote Posts Block plugin <= 1.1.0 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-100681MEDIUMBudibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams WebhookEPSS 0.2%CVE-2024-45206MEDIUMA vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts ofEPSS 0.2%CVE-2025-42965MEDIUMServer Side Request Forgery(SSRF) vulnerability in SAP BusinessObjects BI Platform Central Management Console Promotion Management ApplicationEPSS 0.2%CVE-2026-63743MEDIUMSurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP RedirectEPSS 0.2%CVE-2026-42592MEDIUMGotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routesEPSS 0.2%CVE-2020-14327—A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower sEPSS 0.2%CVE-2026-84395HIGHPremiere Pro | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.2%CVE-2025-13588MEDIUMlKinderBueno Streamity Xtream IPTV Player proxy.php server-side request forgeryEPSS 0.2%CVE-2024-55910MEDIUMIBM Concert Software server-side request forgeryEPSS 0.2%CVE-2025-69239MEDIUMServer-Site Request Forgery in Raytha CMSEPSS 0.2%