Weaknesses of type CWE-918

3,050 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-27152HIGHPossible SSRF and Credential Leakage via Absolute URL in axios RequestsEPSS 0.8%CVE-2025-59503CRITICALAzure Compute Resource Provider Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-54234LOWColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.8%CVE-2022-2556—MailChimp for Woocommerce < 2.7.2 - Admin+ SSRFEPSS 0.8%CVE-2022-24789HIGH Deserialization of untrusted data in C1 CMS.EPSS 0.8%CVE-2021-34811MEDIUMServer-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote EPSS 0.8%CVE-2023-40017HIGHGeonode Server Side Request Forgery vulnerabilityEPSS 0.8%CVE-2023-6852MEDIUMkalcaddle KodExplorer app.php server-side request forgeryEPSS 0.8%CVE-2026-63443HIGHCoder: Workspace agent API insecure redirect handling allowed cross-agent file read and writeEPSS 0.8%CVE-2022-22993HIGHLimited Server-Side Request Forgery vulnerability on Western Digital My Cloud devices.EPSS 0.8%CVE-2024-12882HIGHSSRF in comfyanonymous/comfyuiEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2022-4335MEDIUMA blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 whichEPSS 0.8%CVE-2024-49521HIGHAdobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.7%CVE-2026-26135CRITICALAzure Custom Locations Resource Provider (RP) Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-12376HIGHServer Side Request Forgery in lm-sys/fastchatEPSS 0.7%CVE-2024-12766HIGHSSRF in parisneo/lollms-webuiEPSS 0.7%CVE-2023-1634MEDIUMOTCMS URL Parameter info_deal.php UseCurl server-side request forgeryEPSS 0.7%CVE-2025-57644CRITICALAccela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative useEPSS 0.7%CVE-2025-34231HIGHVasion Print (formerly PrinterLogic) SSRF via HP badgeSetup.phpEPSS 0.7%