Weaknesses of type CWE-918

3,091 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-32828MEDIUMKargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data ExfiltrationEPSS 0.4%CVE-2024-56275MEDIUMWordPress Envato Elements plugin <= 2.0.14 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.4%CVE-2026-4964MEDIUMletta-ai letta File URL message_helper.py _convert_message_create_to_message server-side request forgeryEPSS 0.4%CVE-2026-33540HIGHDistribution affected by pull-through cache credential exfiltration via www-authenticate bearer realmEPSS 0.4%CVE-2026-13739HIGHServer-Side Request Forgery (SSRF)EPSS 0.4%CVE-2026-34504MEDIUMOpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal ProviderEPSS 0.4%CVE-2026-15643CRITICALAWS HealthLake MCP Server SSRF via Pagination URLEPSS 0.4%CVE-2025-2691HIGHVersions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname thEPSS 0.4%CVE-2026-48858MEDIUMftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksEPSS 0.4%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.4%CVE-2025-13281MEDIUMPortworx Half-Blind SSRF in kube-controller-managerEPSS 0.4%CVE-2026-92932MEDIUMMISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF When readFile Is DisabledEPSS 0.4%CVE-2026-5052MEDIUMVault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNSEPSS 0.4%CVE-2026-12473HIGHOHIF Viewers DICOM Server-Side request forgeryEPSS 0.4%CVE-2026-68558HIGHWekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)EPSS 0.4%CVE-2026-91935HIGHFlowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model NodesEPSS 0.4%CVE-2026-42184MEDIUMTauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC CommandsEPSS 0.4%CVE-2026-21653HIGHCCure and Victor Application Server - Server Side Request ForgeryEPSS 0.4%CVE-2026-60033MEDIUMJoomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0EPSS 0.4%CVE-2026-55455MEDIUMAppsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylistEPSS 0.4%