Weaknesses of type CWE-918

3,123 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-1015MEDIUMIBM InfoSphere Information Server is vulnerable to server-side request forgeryEPSS 0.2%CVE-2026-85305MEDIUMWordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-46531MEDIUMWordPress WP AVCL Automation Helper (formerly WPFlyLeads) plugin <= 3.4 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-47664HIGHPathling: $import-pnp operation enables authenticated SSRF, credential leakage, and warehouse data poisoningEPSS 0.2%CVE-2024-34580MEDIUMApache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection agaiEPSS 0.2%CVE-2026-55096HIGHSSRF via DNS-resolution gap in _validate_url_security (file download by URL)EPSS 0.2%CVE-2025-49917MEDIUMWordPress Icegram Express Pro plugin <= 5.9.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-58615MEDIUMWordPress WP Bannerize Pro Plugin <= 1.10.0 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-77112MEDIUMSSRF Leading to JWT Token Disclosure in Global IT Informatics' WeollEPSS 0.2%CVE-2026-39670MEDIUMWordPress Visual Link Preview plugin <= 2.3.0 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2026-66654MEDIUMWordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2026-32467MEDIUMWordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-64511HIGHMaxKB has SSRF in sandboxEPSS 0.2%CVE-2026-77573LOWWeblate: DNS rebinding in VCS operations allows server-side request forgeryEPSS 0.2%CVE-2026-13751MEDIUMSnowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!loadEPSS 0.2%CVE-2025-67427MEDIUMA Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server toEPSS 0.2%CVE-2025-69206MEDIUMHemmelig has SSRF Filter bypass in Secret Request functionalityEPSS 0.2%CVE-2025-49985MEDIUMWordPress Auto Upload Images plugin <= 3.3.2 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2025-49984MEDIUMWordPress PowerPress Podcasting plugin <= 11.13.11 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2025-49418HIGHWordPress Allmart plugin <= 1.0.0 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%