Weaknesses of type CWE-918

3,069 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-53983CRITICALGround Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URLEPSS 0.6%CVE-2026-3750MEDIUMContiNew Admin Storage Management S3ClientFactory.java URI.create server-side request forgeryEPSS 0.6%CVE-2024-47830CRITICALPlane allows server side request forgery via /_next/image endpointEPSS 0.6%CVE-2024-51665MEDIUMWordPress Magical Addons For Elementor plugin <= 1.2.1 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.6%CVE-2024-52602MEDIUMServer-Side Request Forgery (SSRF) on redirects and federation in Matrix Media RepoEPSS 0.6%CVE-2023-39313HIGHWordPress Avada theme <= 7.11.1 - Authenticated Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.6%CVE-2026-41323HIGHKyverno: ServiceAccount token leaked to external servers via apiCall service URLEPSS 0.6%CVE-2026-44335HIGHSSRF bypass in PraisonAIEPSS 0.6%CVE-2023-53899MEDIUMPodcastGenerator 3.2.9 Blind Server-Side Request Forgery via XML InjectionEPSS 0.6%CVE-2026-48736MEDIUMSymfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClientEPSS 0.6%CVE-2025-26494HIGHServer Side Request Forgery vulnerability in Tableau ServerEPSS 0.6%CVE-2023-27271MEDIUMServer Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platformEPSS 0.6%CVE-2026-86119CRITICALWebstudio through 0.296.0 SSRF via /cgi proxy routesEPSS 0.6%CVE-2024-3152HIGHPrivilege Escalation and Local File Inclusion in mintplex-labs/anything-llmEPSS 0.6%CVE-2022-36112LOWBlind Server-Side Request Forgery (SSRF) in GLPIEPSS 0.6%CVE-2026-54204HIGHTeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionalityEPSS 0.6%CVE-2025-0454HIGHSSRF Check Bypass in Requests Utility in significant-gravitas/autogptEPSS 0.6%CVE-2025-22603HIGHAutoGPT SSRF vulnerabilityEPSS 0.6%CVE-2026-5469MEDIUMCasdoor Webhook URL server-side request forgeryEPSS 0.6%CVE-2026-69543HIGHAzure Virtual Machines Elevation of Privilege VulnerabilityEPSS 0.6%