Fallos del tipo CWE-918

3105 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2026-12767MEDIUMLangflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesEPSS 0.2%CVE-2026-12765MEDIUMLangflow OSS is affected by server-side request forgery due to missing URL validation in flow componentsEPSS 0.2%CVE-2026-25428MEDIUMWordPress TS Poll plugin <= 2.5.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-47483MEDIUMWordPress Easy Replace Image plugin <= 3.5.0 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2025-30964MEDIUMWordPress Photography theme < 7.7.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-12388MEDIUMB Carousel Block – Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request ForgeryEPSS 0.2%CVE-2024-45843LOWWeak SSRF FilteringEPSS 0.2%CVE-2024-55089MEDIUMRhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may coEPSS 0.2%CVE-2024-56471MEDIUMIBM Aspera Shares Server-Side Request ForgeryEPSS 0.2%CVE-2025-47664MEDIUMWordPress WP Pipes <= 1.4.2 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2024-56470MEDIUMIBM Aspera Shares Server-Side Request ForgeryEPSS 0.2%CVE-2026-53945MEDIUMGhost: Server-side request forgery via DNS rebinding in external request handlingEPSS 0.2%CVE-2023-31456MEDIUMThere is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitEPSS 0.2%CVE-2025-49374MEDIUMWordPress Captcha.eu plugin <= 1.0.61 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-43747MEDIUMA server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation oEPSS 0.2%CVE-2026-55599MEDIUMphpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information AccessEPSS 0.2%CVE-2025-58962MEDIUMWordPress Publitio Plugin <= 2.2.1 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-54353HIGHBudibase: Potential SSRF DNS rebinding bypass in outbound fetch validationEPSS 0.2%CVE-2025-46511MEDIUMWordPress BeerXML Shortcode plugin <= 0.7.1 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-21887HIGHOpenCTI has a Semi-Blind SSRF via Unvalidated External URL in Data Ingestion FeatureEPSS 0.2%