Fallos del tipo CWE-918

3087 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2026-12473HIGHOHIF Viewers DICOM Server-Side request forgeryEPSS 0.4%CVE-2026-60033MEDIUMJoomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0EPSS 0.4%CVE-2026-68558HIGHWekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)EPSS 0.4%CVE-2026-53930MEDIUMNocoDB: Server-Side Request Forgery via Base Migration URLEPSS 0.4%CVE-2026-91935HIGHFlowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model NodesEPSS 0.4%CVE-2026-53927MEDIUMNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URLEPSS 0.4%CVE-2026-21653HIGHCCure and Victor Application Server - Server Side Request ForgeryEPSS 0.4%CVE-2026-73432MEDIUMStored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookupEPSS 0.4%CVE-2026-44286LOWFastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address ValidationEPSS 0.4%CVE-2026-8081MEDIUMrouter-for-me CLIProxyAPI api_tools.go server-side request forgeryEPSS 0.4%CVE-2026-86590MEDIUMIn Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied EPSS 0.4%CVE-2025-10765MEDIUMSeriaWei ZKEACMS SEOSuggestions ZKEACMS.SEOSuggestions.dll server-side request forgeryEPSS 0.4%CVE-2026-32110HIGHSiYuan has a Full-Read SSRF via /api/network/forwardProxyEPSS 0.4%CVE-2021-47776MEDIUMUmbraco v8.14.1 - 'baseUrl' SSRFEPSS 0.4%CVE-2026-54018HIGHOpen WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP RedirectsEPSS 0.4%CVE-2026-33675MEDIUMVikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network ResourcesEPSS 0.4%CVE-2026-42313HIGHpyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxyEPSS 0.4%CVE-2026-41688HIGHIncomplete fix for CVE-2026-33399: SSRF in WallosEPSS 0.4%CVE-2025-25760HIGHA Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and serviceEPSS 0.4%CVE-2024-13923HIGHOrder Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file FunctionEPSS 0.4%