Fallos del tipo CWE-918

3100 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2026-55166CRITICALLemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOREPSS 0.3%CVE-2026-19301MEDIUMLangflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple componentsEPSS 0.3%CVE-2025-27232MEDIUMFrontend arbitrary file read in oauth.authorize actionEPSS 0.3%CVE-2026-76347MEDIUMServer-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure GatewayEPSS 0.3%CVE-2024-33634MEDIUMWordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2024-37260HIGHWordPress Foxiz Theme theme <= 2.3.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-3048MEDIUMNexus Repository 3 - Improper LDAP Referral HandlingEPSS 0.3%CVE-2025-1662MEDIUMURL Media Uploader <= 1.0.0 - Authenticated (Author+) Server-Side Request Forgery via DNS RebindingEPSS 0.3%CVE-2026-44430MEDIUMMCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlistEPSS 0.3%CVE-2025-9799LOWLangfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgeryEPSS 0.3%CVE-2026-84301MEDIUMFastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requestsEPSS 0.3%CVE-2025-13378MEDIUMAI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' ParameterEPSS 0.3%CVE-2024-13697MEDIUMBetter Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_linksEPSS 0.3%CVE-2025-10096MEDIUMSimStudioAI sim route.ts server-side request forgeryEPSS 0.3%CVE-2024-37098MEDIUMWordPress BlossomThemes Email Newsletter plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2024-43379LOWTruffleHog has a Blind SSRF in some DetectorsEPSS 0.3%CVE-2024-13957HIGHSSRF Server Side Request ForgeryEPSS 0.3%CVE-2024-11836HIGHServer-side Request ForgeryEPSS 0.3%CVE-2025-5260HIGHSSRF in PozitifIK's Pik OnlineEPSS 0.3%CVE-2025-28092MEDIUMShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.EPSS 0.3%