Weaknesses of type CWE-918

3,108 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-69239MEDIUMServer-Site Request Forgery in Raytha CMSEPSS 0.2%CVE-2024-55910MEDIUMIBM Concert Software server-side request forgeryEPSS 0.2%CVE-2026-53513CRITICALBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationEPSS 0.2%CVE-2024-34581HIGHThe W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is EPSS 0.2%CVE-2025-59346MEDIUMDragonfly server-side request forgery vulnerabilityEPSS 0.2%CVE-2025-6242HIGHVllm: server side request forgery (ssrf) in mediaconnectorEPSS 0.2%CVE-2025-60319MEDIUMPerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint EPSS 0.2%CVE-2025-53641HIGHPostiz allows header mutation in middleware facilitates resulting in SSRFEPSS 0.2%CVE-2025-49430HIGHWordPress Ultimate Video Player Plugin <= 10.1 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-10546HIGHDNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL ComponentEPSS 0.2%CVE-2025-50234MEDIUMMCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter isEPSS 0.2%CVE-2026-100863MEDIUMHeym before 0.0.91 SSRF via image fetching and IPv6 validationEPSS 0.2%CVE-2026-25385MEDIUMWordPress URL Shortify plugin <= 1.12.3 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2026-93384LOWServer-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engEPSS 0.2%CVE-2026-59291LOWPotential arbitrary file read and SSRF vulnerability in Spring Cloud FunctionEPSS 0.2%CVE-2025-27430LOWServer Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)EPSS 0.2%CVE-2026-74247MEDIUMQuay: ssrf via build archive_url in quay build apiEPSS 0.2%CVE-2026-23768MEDIUMlucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListenEPSS 0.2%CVE-2026-12971LOWLearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_featureEPSS 0.2%CVE-2023-6070MEDIUM A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary cEPSS 0.2%