Weaknesses of type CWE-918

3,096 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2025-29454MEDIUMAn issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the UpEPSS 0.4%CVE-2025-29455MEDIUMAn issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the TrEPSS 0.4%CVE-2025-29449MEDIUMAn issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.EPSS 0.4%CVE-2026-28451MEDIUMOpenClaw < 2026.2.14 - SSRF via Feishu Extension Media FetchingEPSS 0.4%CVE-2025-29450MEDIUMAn issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.EPSS 0.4%CVE-2025-62615CRITICALAutoGPT has SSRF vulnerability in ReadRSSFeedBlockEPSS 0.4%CVE-2026-57126HIGHpraisonaiagents: SSRF guard validates literal IPs only and never resolves DNSEPSS 0.4%CVE-2025-9960MEDIUMis-localhost-ip 2.0.0 - SSRF via Restrictions bypassEPSS 0.4%CVE-2025-29456MEDIUMAn issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the crEPSS 0.4%CVE-2025-29453MEDIUMAn issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the myEPSS 0.4%CVE-2026-25493MEDIUMCraft has a SSRF in GraphQL Asset Mutation via HTTP RedirectEPSS 0.4%CVE-2026-25494MEDIUMCraft has a SSRF in GraphQL Asset Mutation via Alternative IP NotationEPSS 0.4%CVE-2026-3681MEDIUMwelovemedia FFmate webhook.go fireWebhook server-side request forgeryEPSS 0.4%CVE-2023-3577LOWLimited blind SSRF to localhost/intranet in interactive dialog implementationEPSS 0.4%CVE-2023-7325CRITICALMingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRFEPSS 0.4%CVE-2026-82905MEDIUMsdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgeryEPSS 0.4%CVE-2026-88001MEDIUMOpen WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targetsEPSS 0.4%CVE-2026-6616MEDIUMTransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgeryEPSS 0.4%CVE-2024-4562MEDIUMWhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via HttpMonitorSettingsEPSS 0.4%CVE-2026-35409HIGHDirectus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File ImportEPSS 0.4%