Weaknesses of type CWE-918

3,076 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-1848MEDIUMzj1983 zz import_data_check server-side request forgeryEPSS 0.5%CVE-2025-1833MEDIUMzj1983 zz HTTP Request Customer_noticeAction.java sendNotice server-side request forgeryEPSS 0.5%CVE-2025-65512HIGHA Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 anEPSS 0.5%CVE-2024-5015HIGHWhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-65842HIGHPlate: SSRF with response disclosure in DOCX image embeddingEPSS 0.5%CVE-2025-1211MEDIUMVersions of the package hackney before 1.21.0 are vulnerable to Server-side Request Forgery (SSRF) due to improper parsing of URLs by URI buEPSS 0.5%CVE-2023-27896MEDIUMServer Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platformEPSS 0.5%CVE-2026-66901HIGHGoogle::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSONEPSS 0.5%CVE-2026-81093HIGHApify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeletonEPSS 0.5%CVE-2024-36427HIGHThe file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to EPSS 0.5%CVE-2026-54607HIGHFastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)EPSS 0.5%CVE-2025-5327MEDIUMchshcms mccms Gf.php index server-side request forgeryEPSS 0.5%CVE-2024-10044CRITICALSSRF in POST /worker_generate_stream API endpoint in lm-sys/fastchatEPSS 0.5%CVE-2026-54017HIGHOpen WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversalEPSS 0.5%CVE-2024-13029MEDIUMAntabot White-Jotter Edit Book book server-side request forgeryEPSS 0.5%CVE-2026-54452MEDIUMsafeurl: Missing IPv6 CIDR Ranges in BlocklistEPSS 0.5%CVE-2026-62240HIGHCrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape ToolsEPSS 0.5%CVE-2024-3149CRITICALSSRF in mintplex-labs/anything-llmEPSS 0.5%CVE-2025-0584MEDIUMaEnrich Technology a+HRD - Server-Side Request Forgery (SSRF)EPSS 0.5%CVE-2026-18952HIGHMissing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics PluginEPSS 0.5%