Fallos del tipo CWE-918

3091 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2023-45705LOWHCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF)EPSS 0.4%CVE-2026-48918MEDIUMJenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.EPSS 0.4%CVE-2023-37230HIGHLoftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.EPSS 0.4%CVE-2026-46717HIGHNezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notificationEPSS 0.4%CVE-2023-37229HIGHLoftware Spectrum before 5.1 allows SSRF.EPSS 0.4%CVE-2025-66405MEDIUMPortkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom HostEPSS 0.4%CVE-2025-55151HIGHStirling-PDF SSRF vulnerability on /api/v1/convert/file/pdfEPSS 0.4%CVE-2026-30953HIGHLinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequestEPSS 0.4%CVE-2023-26459HIGHServer Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.4%CVE-2026-77822HIGHIBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpointEPSS 0.4%CVE-2026-55113HIGHA malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk ApplicatioEPSS 0.4%CVE-2026-69246HIGHGuzzle: Noncanonical host can bypass host-based checksEPSS 0.4%CVE-2026-72598MEDIUMApioo Fusio - Server-Side Request ForgeryEPSS 0.4%CVE-2026-45561MEDIUMRoxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPsEPSS 0.4%CVE-2026-72591HIGHKoito - Authenticated Server-Side Request Forgery via Album Image URL ParameterEPSS 0.4%CVE-2026-29925HIGHInvoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.EPSS 0.4%CVE-2025-8133MEDIUMyanyutao0402 ChanCMS gather.js getArticle server-side request forgeryEPSS 0.4%CVE-2026-91079MEDIUMHuly Platform through 0.7.426 SSRF via Print ServiceEPSS 0.4%CVE-2026-49120MEDIUMMedplum < 5.1.14 SSRF via FHIR Subscription EndpointEPSS 0.4%CVE-2024-31288HIGHWordPress RapidLoad plugin <= 2.2.11 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.4%