Falhas do tipo CWE-918

3.100 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2026-55166CRITICALLemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOREPSS 0.3%CVE-2026-19301MEDIUMLangflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple componentsEPSS 0.3%CVE-2025-27232MEDIUMFrontend arbitrary file read in oauth.authorize actionEPSS 0.3%CVE-2026-76347MEDIUMServer-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure GatewayEPSS 0.3%CVE-2024-33634MEDIUMWordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2024-37260HIGHWordPress Foxiz Theme theme <= 2.3.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-3048MEDIUMNexus Repository 3 - Improper LDAP Referral HandlingEPSS 0.3%CVE-2025-1662MEDIUMURL Media Uploader <= 1.0.0 - Authenticated (Author+) Server-Side Request Forgery via DNS RebindingEPSS 0.3%CVE-2026-44430MEDIUMMCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlistEPSS 0.3%CVE-2025-9799LOWLangfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgeryEPSS 0.3%CVE-2026-84301MEDIUMFastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requestsEPSS 0.3%CVE-2025-13378MEDIUMAI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' ParameterEPSS 0.3%CVE-2024-13697MEDIUMBetter Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_linksEPSS 0.3%CVE-2025-10096MEDIUMSimStudioAI sim route.ts server-side request forgeryEPSS 0.3%CVE-2024-37098MEDIUMWordPress BlossomThemes Email Newsletter plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2024-43379LOWTruffleHog has a Blind SSRF in some DetectorsEPSS 0.3%CVE-2024-13957HIGHSSRF Server Side Request ForgeryEPSS 0.3%CVE-2024-11836HIGHServer-side Request ForgeryEPSS 0.3%CVE-2025-5260HIGHSSRF in PozitifIK's Pik OnlineEPSS 0.3%CVE-2025-28092MEDIUMShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.EPSS 0.3%