Falhas do tipo CWE-918

3.097 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2024-52594MEDIUMServer-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlibEPSS 0.3%CVE-2024-5186HIGHServer Side Request Forgery (SSRF) in imartinez/privategptEPSS 0.3%CVE-2026-39368MEDIUMWWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal servicesEPSS 0.3%CVE-2026-33682MEDIUMStreamlit on Windows has Unauthenticated SSRF Vulnerability (NTLM Credential Exposure)EPSS 0.3%CVE-2026-26019MEDIUM@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validationEPSS 0.3%CVE-2025-9975MEDIUMWP Scraper <= 5.8.1 - Authenticated (Administrator+) Server-Side Request ForgeryEPSS 0.3%CVE-2026-91967MEDIUMAVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURLEPSS 0.3%CVE-2026-20958MEDIUMMicrosoft SharePoint Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-27907MEDIUMIBM WebSphere Application Server server-side request forgeryEPSS 0.3%CVE-2025-64522CRITICALSoft Serve is vulnerable to SSRF through its WebhooksEPSS 0.3%CVE-2026-92569MEDIUMHippo4j through 1.5.0 SSRF via clientAddress ParameterEPSS 0.3%CVE-2026-75754CRITICALMissing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center aEPSS 0.3%CVE-2024-10705MEDIUMMultiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrlEPSS 0.3%CVE-2026-41271HIGHFlowise: APIChain Prompt Injection SSRF in GET/POST API ChainsEPSS 0.3%CVE-2026-55535MEDIUMPraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validationEPSS 0.3%CVE-2026-91199MEDIUMRefly through 1.1.0 Server-Side Request Forgery via scrape endpointEPSS 0.3%CVE-2024-27949MEDIUMWordPress Sirv plugin <= 7.2.0 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-22681HIGHOpenViking < 0.3.4 SSRF via /api/v1/resourcesEPSS 0.3%CVE-2023-6805MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)EPSS 0.3%CVE-2026-4328MEDIUMAdvanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' ParameterEPSS 0.3%