Weaknesses of type CWE-918

3,097 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2023-45705LOWHCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF)EPSS 0.4%CVE-2026-48918MEDIUMJenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.EPSS 0.4%CVE-2025-66405MEDIUMPortkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom HostEPSS 0.4%CVE-2026-45561MEDIUMRoxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPsEPSS 0.4%CVE-2026-77822HIGHIBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpointEPSS 0.4%CVE-2026-30953HIGHLinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequestEPSS 0.4%CVE-2026-46717HIGHNezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notificationEPSS 0.4%CVE-2026-72598MEDIUMApioo Fusio - Server-Side Request ForgeryEPSS 0.4%CVE-2023-26459HIGHServer Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.4%CVE-2023-37229HIGHLoftware Spectrum before 5.1 allows SSRF.EPSS 0.4%CVE-2025-55151HIGHStirling-PDF SSRF vulnerability on /api/v1/convert/file/pdfEPSS 0.4%CVE-2026-55113HIGHA malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk ApplicatioEPSS 0.4%CVE-2026-69246HIGHGuzzle: Noncanonical host can bypass host-based checksEPSS 0.4%CVE-2023-37230HIGHLoftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.EPSS 0.4%CVE-2026-29925HIGHInvoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.EPSS 0.4%CVE-2026-72591HIGHKoito - Authenticated Server-Side Request Forgery via Album Image URL ParameterEPSS 0.4%CVE-2024-20332MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker EPSS 0.4%CVE-2026-56769MEDIUMHuly Platform - Server-Side Request Forgery via /import EndpointEPSS 0.4%CVE-2026-49120MEDIUMMedplum < 5.1.14 SSRF via FHIR Subscription EndpointEPSS 0.4%CVE-2026-49979MEDIUMAppsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP FilterEPSS 0.4%