Falhas do tipo CWE-918

3.097 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2017-20106MEDIUMLithium Forum Compose Message server-side request forgeryEPSS 0.3%CVE-2019-25251MEDIUMTeradek VidiU Pro 3.0.3 Server-Side Request Forgery via RTMP SettingsEPSS 0.3%CVE-2026-82243HIGHBudibase Server before 3.41.3 SSRF with Credential LeakageEPSS 0.3%CVE-2026-54299HIGHAstro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)EPSS 0.3%CVE-2025-8020HIGHAll versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname EPSS 0.3%CVE-2025-8341MEDIUMSSRF in Infinity Datasource PluginEPSS 0.3%CVE-2025-9269MEDIUMServer-Side Request Forgery (SSRF) vulnerability found in embedded web serverEPSS 0.3%CVE-2025-70042CRITICALAn issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.EPSS 0.3%CVE-2026-41270HIGHFlowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxEPSS 0.3%CVE-2025-45475MEDIUMmaccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.EPSS 0.3%CVE-2019-25451MEDIUMphpMoAdmin 1.1.5 Cross-Site Request Forgery via moadmin.phpEPSS 0.3%CVE-2025-68662HIGHFinalDestination hostname matching allows SSRF protection bypassEPSS 0.3%CVE-2026-41687MEDIUMWallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline ChecksEPSS 0.3%CVE-2026-25738MEDIUMIndico has Server-Side Request Forgery (SSRF) in multiple placesEPSS 0.3%CVE-2026-68927LOWMobSF: SSRF port restriction bypass in assetlinks_checkEPSS 0.3%CVE-2026-11370MEDIUMWP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' ParameterEPSS 0.3%CVE-2024-9410MEDIUMAda.cx SSRF via Sentry MisconfigurationEPSS 0.3%CVE-2026-92568MEDIUMMLRun through 1.11.0 Server-Side Request Forgery via WebhookEPSS 0.3%CVE-2026-47879HIGHSpring Cloud Gateway SSRF and native file access with gRPCEPSS 0.3%CVE-2026-48483MEDIUMTypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot serverEPSS 0.3%