Weaknesses of type CWE-918

3,054 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2022-36451HIGHA vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conductEPSS 0.6%CVE-2026-88056HIGHAngular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSREPSS 0.6%CVE-2026-47356HIGHTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POEPSS 0.6%CVE-2026-54885MEDIUMServer-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetchingEPSS 0.6%CVE-2026-54735CRITICALprebid-server's request forgery vulnerability allows for possible host environment data extractionEPSS 0.6%CVE-2026-29226HIGHApache OFBiz: Low-Privilege SSRF in Content ComponentEPSS 0.6%CVE-2024-44721CRITICALSeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.EPSS 0.6%CVE-2026-55245HIGHBifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURLEPSS 0.6%CVE-2026-26801HIGHServer-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitiveEPSS 0.6%CVE-2026-47358CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when EPSS 0.6%CVE-2026-42213MEDIUMSolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leakEPSS 0.6%CVE-2026-72552HIGHDub Dub - Server-Side Request ForgeryEPSS 0.6%CVE-2024-22648MEDIUMA Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attaEPSS 0.6%CVE-2023-34959MEDIUMAn issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the seEPSS 0.6%CVE-2026-30637HIGHServer-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerabiEPSS 0.6%CVE-2023-47619HIGHAudiobookshelf Server-Side Request Forgery and Arbitrary File Read VulnerabilityEPSS 0.6%CVE-2023-1895HIGHGetwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request ForgeryEPSS 0.6%CVE-2026-86806MEDIUMopengeos GeoLibre _is_within_roots server-side request forgeryEPSS 0.6%CVE-2026-15330MEDIUMzhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgeryEPSS 0.6%CVE-2023-6570HIGHServer-Side Request Forgery (SSRF) in kubeflow/kubeflowEPSS 0.6%