Weaknesses of type CWE-918

3,124 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-59436LOWThe ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as EPSS 0.1%CVE-2024-42182LOWHCL BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerabilityEPSS 0.1%CVE-2026-19504MEDIUMFabric.js loadFromJSON Server-Side Request Forgery VulnerabilityEPSS 0.1%CVE-2025-62341LOWHCL Connections is vulnerable to server-side request forgery (SSRF)EPSS 0.1%CVE-2026-31959MEDIUMSSRF in Quill via unvalidated URL from Apple notarization log retrievalEPSS 0.1%CVE-2026-18066HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2023-21105—In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local EPSS 0.1%CVE-2026-102095CRITICALKiteworks Email Protection Gateway server-side request forgeryEPSS —CVE-2026-102104CRITICALKiteworks Email Protection Gateway server-side request forgeryEPSS —CVE-2026-102091HIGHKiteworks Secure Data Forms server-side request forgeryEPSS —CVE-2023-54402HIGHiDocView SSRF via /doc/upload Endpoint Hardcoded TokenEPSS —CVE-2026-62308CRITICALTugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpointEPSS —CVE-2026-103530MEDIUMdecolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgeryEPSS —CVE-2026-102138LOWKiteworks Core Server-Side Request Forgery (SSRF)EPSS —CVE-2026-55177HIGHCloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched with no IP-classification guardEPSS —CVE-2026-103243MEDIUMLightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpointsEPSS —CVE-2026-100257MEDIUMIn JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF exportEPSS —CVE-2026-102102CRITICALKiteworks Email Protection Gateway server-side request forgeryEPSS —CVE-2026-100279MEDIUMIn JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentialsEPSS —CVE-2026-102983MEDIUMAstro: Netlify Image CDN allowlist bypass enables SSRFEPSS —