Weaknesses of type CWE-918

3,097 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2026-92184MEDIUMag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgeryEPSS 0.4%CVE-2026-5803MEDIUMbigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgeryEPSS 0.4%CVE-2026-90790MEDIUMa2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch_notification server-side request forgeryEPSS 0.4%CVE-2024-53983MEDIUMServer-side request forgery in Backstage Scaffolder pluginEPSS 0.4%CVE-2025-44594CRITICALhalo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-EPSS 0.4%CVE-2026-33234MEDIUMAutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP serverEPSS 0.4%CVE-2026-27945LOWZITADEL has potential SSRF via ActionsEPSS 0.4%CVE-2026-91938HIGHFlowise before 3.1.4 Server-Side Request Forgery via document loadersEPSS 0.4%CVE-2023-29008HIGHSvelteKit framework has Insufficient CSRF protection for CORS requestsEPSS 0.4%CVE-2026-86122MEDIUMRowboat through 0.9.1 Server-Side Request Forgery via Custom MCP ServerEPSS 0.4%CVE-2026-54546MEDIUMCloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guardEPSS 0.4%CVE-2026-56663HIGHAutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` accessEPSS 0.4%CVE-2026-42335MEDIUMMaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing DiscrepancyEPSS 0.4%CVE-2026-33975HIGHtwenty-server SSRF protection bypass via IPv4-mapped IPv6 address normalizationEPSS 0.4%CVE-2026-30839MEDIUMWallos: SSRF via webhook test endpointEPSS 0.4%CVE-2026-45741HIGHGotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixesEPSS 0.4%CVE-2026-26379MEDIUMKoha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows auEPSS 0.4%CVE-2026-88896MEDIUMEspoCRM before 10.0.4 SSRF via IPv6 Transition Address BypassEPSS 0.4%CVE-2026-48918MEDIUMJenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.EPSS 0.4%CVE-2024-13905MEDIUMOneStore Sites <= 0.1.1 - Unauthenticated Blind Server-Side Request ForgeryEPSS 0.4%