Weaknesses of type CWE-918

3,062 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2023-1725CRITICALSSRF in Infoline Project Management SystemEPSS 0.6%CVE-2026-65317CRITICALVerba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware BypassEPSS 0.6%CVE-2026-45502MEDIUMMicrosoft Exchange Server Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-28824MEDIUMServer-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected pEPSS 0.6%CVE-2024-45479CRITICALApache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhostEPSS 0.6%CVE-2023-0574MEDIUMServer-Side Request ForgeryEPSS 0.6%CVE-2025-32013CRITICALServer-Side Request Forgery via LNURL Authentication Callback in LNbits Lightning Network Payment SystemEPSS 0.6%CVE-2023-1971MEDIUMyuan1994 tpAdmin Upload.php remote server-side request forgeryEPSS 0.6%CVE-2026-82097HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.6%CVE-2024-47049HIGHThe czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrlEPSS 0.6%CVE-2024-0440CRITICALSSRF - file:// unsanitized access to underlying host filesEPSS 0.6%CVE-2026-49345MEDIUMMercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.6%CVE-2026-65818HIGHPower Automate Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-57211MEDIUMRabbitMQ: UNC SSRF affecting the management UI on WindowsEPSS 0.6%CVE-2023-46729CRITICALSentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpointEPSS 0.6%CVE-2022-39276LOWBlind Server-Side Request Forgery (SSRF) in RSS feeds and planningEPSS 0.6%CVE-2025-1522HIGHPostHog database_schema Server-Side Request Forgery Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-58189HIGHApache Traffic Server: Plugins resetting the redirect counter enable SSRF amplificationEPSS 0.6%CVE-2026-17123HIGHRoyal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' SettingEPSS 0.6%CVE-2025-27090MEDIUMServer-Side Request Forgery (SSRF) in sliver teamserverEPSS 0.6%