Weaknesses of type CWE-918

3,124 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-19770MEDIUMfeedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgeryEPSS 0.1%CVE-2026-86503LOWIn JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetchingEPSS 0.1%CVE-2026-97316MEDIUMBroken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect BypassEPSS 0.1%CVE-2025-68600MEDIUMWordPress Link Library plugin <= 7.8.7 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.1%CVE-2025-36243MEDIUMMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2022-29840MEDIUMServer Side Request Forgery Vulnerability in Western Digital My Cloud DevicesEPSS 0.1%CVE-2025-68893MEDIUMWordPress WordPress Image shrinker plugin <= 1.1.0 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.1%CVE-2026-46380MEDIUMcompliance-trestle Vulnerable to SSRF in Remote Fetching SubsystemEPSS 0.1%CVE-2026-100577MEDIUMOpenClaw before 2026.8.1 Server-Side Request Forgery via Video AssetEPSS 0.1%CVE-2026-49860MEDIUMDeno: WebSocket API sandbox bypass via missing post-DNS checkEPSS 0.1%CVE-2026-49859MEDIUMDeno: `fetch()` API sandbox bypass via missing DNS resolution checkEPSS 0.1%CVE-2025-49335MEDIUMWordPress External Media plugin <= 1.0.36 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.1%CVE-2026-4339MEDIUMSSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP serverEPSS 0.1%CVE-2026-5323MEDIUMpriyankark a11y-mcp index.js A11yServer server-side request forgeryEPSS 0.1%CVE-2024-30125MEDIUMHCL BigFix Compliance is affected by an internal server errorEPSS 0.1%CVE-2026-14540HIGHServer-Side Request Forgery via Unrestricted HTTP Redirection in MCP ToolboxEPSS 0.1%CVE-2026-96747MEDIUMForced local Unix socket connection via dot-sock KMS endpoint in client-side field encryptionEPSS 0.1%CVE-2026-44363MEDIUMUnsafe remote resource fetching in expansion misp-modulesEPSS 0.1%CVE-2026-24231MEDIUMNVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-sideEPSS 0.1%CVE-2025-59437LOWThe ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally roEPSS 0.1%