Weaknesses of type CWE-918

3,087 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-73307MEDIUMBudibase: SSRF via bare fetch() in uploadUrl during AI table generationEPSS 0.4%CVE-2026-44023HIGHDocling Core has unsafe remote filename resolutionEPSS 0.4%CVE-2026-19040MEDIUMMissionSquad mcp-api dcrClients.ts server-side request forgeryEPSS 0.4%CVE-2026-54508MEDIUMTREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolutionEPSS 0.4%CVE-2026-33480HIGHAVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks ProxyEPSS 0.4%CVE-2024-4561MEDIUMWhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via FaviconControllerEPSS 0.4%CVE-2026-73530MEDIUMFlyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()EPSS 0.4%CVE-2025-4581MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.4%CVE-2024-13195MEDIUMdonglight bookstore电商书城系统说明 HttpUtil.java getHtml server-side request forgeryEPSS 0.4%CVE-2024-9624HIGHWP All Import Pro <= 4.9.3 - Authenticated (Administrator+) Server-Side Request Forgery via File ImportEPSS 0.4%CVE-2026-58442MEDIUMRepository migration SSRF via multi-answer DNS allow-list bypassEPSS 0.4%CVE-2026-43884HIGHWWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()EPSS 0.4%CVE-2026-91081MEDIUMDocs through 5.6.1 SSRF via Unauthenticated cors-proxy EndpointEPSS 0.4%CVE-2026-41177MEDIUMSquidex has Blind SSRF via file:// Protocol in Restore API leading to Local File InteractionEPSS 0.4%CVE-2026-61559CRITICAL@zereight/mcp-gitlab Vulnerable to Server-Side Request ForgeryEPSS 0.4%CVE-2026-28476MEDIUMOpenClaw < 2026.2.14 - Server-Side Request Forgery in Tlon Extension AuthenticationEPSS 0.4%CVE-2024-51242MEDIUMA Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipuEPSS 0.4%CVE-2026-44937HIGHSUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL ComponentsEPSS 0.4%CVE-2026-48555MEDIUMSpatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl()EPSS 0.4%CVE-2026-39885HIGHFrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI SpecificationsEPSS 0.4%