Falhas do tipo CWE-918

3.099 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2026-86735MEDIUMsnipe-it before 8.7.0 SSRF via IPv6 transition address bypassEPSS 0.3%CVE-2026-10526MEDIUMEmbedPress < 4.6.1 - Unauthenticated Blind SSRFEPSS 0.3%CVE-2026-77310MEDIUMjackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)EPSS 0.3%CVE-2026-48998MEDIUMguzzlehttp/psr7 has Host Confusion via Authority ReinterpretationEPSS 0.3%CVE-2026-18597HIGHBlind SSRF on Foxit PDF Services APIEPSS 0.3%CVE-2026-42430MEDIUMOpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect HandlingEPSS 0.3%CVE-2025-48383HIGHDjango-Select2 Vulnerable to Widget Instance Secret Cache Key LeakingEPSS 0.3%CVE-2025-11242CRITICALSSRF in Teknolist Computer's OkulistikEPSS 0.3%CVE-2023-46641MEDIUMWordPress 12 Step Meeting List Plugin <= 3.14.24 is vulnerable to Server Side Request Forgery (SSRF)EPSS 0.3%CVE-2026-52840LOWEasy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal networkEPSS 0.3%CVE-2025-10453MEDIUMPilotGaea Technologies|O'View MapServer - Server-Side Request ForgeryEPSS 0.3%CVE-2026-40072LOWweb3.py affected by SSRF via CCIP Read (EIP-3668) OffchainLookup URL handlingEPSS 0.3%CVE-2025-62719LOWLinkAce: Limited Server-Side Request Forgery (SSRF) in Keyword Fetching FunctionalityEPSS 0.3%CVE-2025-64180CRITICALManager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)EPSS 0.3%CVE-2026-61681MEDIUMHatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation HandlerEPSS 0.3%CVE-2025-11286MEDIUMsamanhappy MCPHub MCPRouter Service serverController.ts server-side request forgeryEPSS 0.3%CVE-2026-26286HIGHSillyTavern has Server-Side Request Forgery (SSRF) via Asset Download Endpoint that Allows Reading Internal ServicesEPSS 0.3%CVE-2026-79635HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side RequesEPSS 0.3%CVE-2026-1294HIGHAll In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-proxy EndpointEPSS 0.3%CVE-2024-13411MEDIUMZapier for WordPress <= 1.5.1 - Authenticated (Subscriber+) Blind Server-Side Request Forgery via updated_user FunctionEPSS 0.3%