Weaknesses of type CWE-918

3,049 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2024-27347MEDIUMApache HugeGraph-Hubble: SSRF in Hubble connection pageEPSS 1.0%CVE-2026-85917HIGHAzure AI Foundry Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2024-22205CRITICALWhoogle Search Server Side Request Forgery vulnerabilityEPSS 1.0%CVE-2019-6837—A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.EPSS 1.0%CVE-2021-25972MEDIUMCamaleon CMS - Server-Side Request Forgery (SSRF) in Media Upload FeatureEPSS 1.0%CVE-2024-51980MEDIUMUnauthenticated Server Side Request Forgery (SSRF) via WS-Addressing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.EPSS 1.0%CVE-2022-0767CRITICALServer-Side Request Forgery (SSRF) in janeczku/calibre-webEPSS 1.0%CVE-2023-50731CRITICALMindsDB has arbitrary file write in file.pyEPSS 1.0%CVE-2023-25195HIGHApache Fineract: SSRF template type vulnerability in certain authenticated usersEPSS 1.0%CVE-2024-0759HIGHCollection of internally resolving IPsEPSS 1.0%CVE-2026-66304HIGHSkype for Business Information Disclosure VulnerabilityEPSS 1.0%CVE-2026-66800HIGHAzure Data Factory Information Disclosure VulnerabilityEPSS 1.0%CVE-2026-26139HIGHMicrosoft Purview Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2021-33181MEDIUMServer-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticateEPSS 1.0%CVE-2025-6087HIGHSSRF vulnerability in opennextjs-cloudflare via /_next/image endpointEPSS 1.0%CVE-2022-36376MEDIUMWordPress Rank Math SEO plugin <= 1.0.95 - Server-Side Request Forgery (SSRF) vulnerabilityEPSS 1.0%CVE-2023-27161HIGHJellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability alEPSS 1.0%CVE-2023-41055HIGHLibreY Server-Side Request Forgery (SSRF) vulnerability via wikipedia_language cookieEPSS 1.0%CVE-2025-34350HIGHUnForm Server < 10.1.15 Doc Flow Unauthenticated File ReadEPSS 1.0%CVE-2022-0339MEDIUMServer-Side Request Forgery (SSRF) in janeczku/calibre-webEPSS 1.0%