Weaknesses of type CWE-918

3,069 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2024-2057MEDIUMLangChain langchain_community TFIDFRetriever tfidf.py load_local server-side request forgeryEPSS 0.6%CVE-2024-45317HIGHA Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenEPSS 0.6%CVE-2022-1213HIGHSSRF filter bypass port 80, 433 in livehelperchat/livehelperchatEPSS 0.6%CVE-2026-80150HIGHLantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl ParameterEPSS 0.6%CVE-2026-80149HIGHLantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl ParameterEPSS 0.6%CVE-2024-41668HIGHcBioPortal Proxy Endpoint VulnerabliityEPSS 0.6%CVE-2026-80148HIGHLantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username TruncationEPSS 0.6%CVE-2025-27774HIGHApplio allows SSRF and file write in model_download.pyEPSS 0.6%CVE-2025-27776HIGHApplio allows SSRF and file write in model_download.pyEPSS 0.6%CVE-2026-42043HIGHAxios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0EPSS 0.6%CVE-2026-42404MEDIUMApache Neethi: Unrestricted HTTP Redirect Following in Policy ReferencesEPSS 0.6%CVE-2026-69904LOWMicrosoft Office SharePoint Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-57866HIGHApache Impala: Secrets Exfiltration via SSRFEPSS 0.6%CVE-2025-0292MEDIUMSSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attackeEPSS 0.6%CVE-2024-4851HIGHSSRF Vulnerability in stangirard/quivrEPSS 0.6%CVE-2026-62993MEDIUMSmarty: SSRF via redirect bypass of trusted_uri using {fetch}EPSS 0.6%CVE-2026-34160HIGHChamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata servicesEPSS 0.6%CVE-2024-1467MEDIUMStarter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.1.6 - Authenticated (Contributor+) Server-Side Request ForgeryEPSS 0.6%CVE-2022-30579HIGHTIBCO Spotfire Server Blind SSRF vulnerabilityEPSS 0.6%CVE-2026-53983CRITICALGround Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URLEPSS 0.6%