Falhas do tipo CWE-918

3.099 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2026-62216LOWOpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media UploadEPSS 0.3%CVE-2025-14277MEDIUMPrime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request ForgeryEPSS 0.3%CVE-2026-21885MEDIUMMiniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resourcesEPSS 0.3%CVE-2026-77069LOWn8n before 1.123.69 SSRF Protection Bypass via OAuth2EPSS 0.3%CVE-2026-76086HIGHFormie: Integration form-settings action allows SSRF and exfiltration of stored integration credentialsEPSS 0.3%CVE-2025-15098MEDIUMYunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgeryEPSS 0.3%CVE-2024-33627MEDIUMWordPress AGCA – Custom Dashboard & Login Page plugin <= 7.2.2 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2024-32454MEDIUMWordPress Wappointment plugin <= 2.6.0 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2025-66201HIGHLibreChat is Vulnerable to Server-Side Request Forgery (SSRF) in Actions CapabilityEPSS 0.3%CVE-2025-33203HIGHNVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request ForEPSS 0.3%CVE-2024-25181CRITICALA critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary filEPSS 0.3%CVE-2026-18730HIGHServer-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer tokenEPSS 0.3%CVE-2025-47548MEDIUMWordPress Wbcom Designs - Activity Link Preview For BuddyPress plugin <= 1.4.4 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.3%CVE-2024-9408HIGHIn Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.EPSS 0.3%CVE-2026-23603LOWBlind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimEPSS 0.3%CVE-2026-85528MEDIUMSnowflake JDBC Driver auto-configuration account validation permits credential redirectionEPSS 0.3%CVE-2026-33294MEDIUMAVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network ResourcesEPSS 0.3%CVE-2026-81207HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.3%CVE-2026-53450HIGHCoturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protectionEPSS 0.3%CVE-2026-71211HIGHmlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy EndpointEPSS 0.3%