Falhas do tipo CWE-918

3.105 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2023-6070MEDIUM A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary cEPSS 0.2%CVE-2024-13940MEDIUMNinja Forms Webhooks <= 3.0.7 - Authenticated (Admin+) Server-Side Request Forgery via Form WebhookEPSS 0.2%CVE-2026-101064HIGHObot before v0.23.0 Server-Side Request Forgery via MCPEPSS 0.2%CVE-2026-21294MEDIUMAdobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.2%CVE-2026-21293MEDIUMAdobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.2%CVE-2026-65593MEDIUMn8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node ParametersEPSS 0.2%CVE-2026-55524HIGHPraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)EPSS 0.2%CVE-2026-72784MEDIUMCraft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutationEPSS 0.2%CVE-2026-20041MEDIUMCisco Nexus Dashboard Server Side Request Forgery VulnerabilityEPSS 0.2%CVE-2025-64427HIGHZimaOS is vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.2%CVE-2024-35637MEDIUMWordPress Church Admin plugin <= 4.3.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2024-39739MEDIUMIBM Datacap Navigator server-side request forgeryEPSS 0.2%CVE-2023-22817MEDIUMServer-side Request Forgery vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi productsEPSS 0.2%CVE-2023-46945CRITICALQD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted requestEPSS 0.2%CVE-2025-59146HIGHNew API has Authenticated Server-Side Request Forgery (SSRF) issueEPSS 0.2%CVE-2024-11913MEDIUMActivity Plus Reloaded for BuddyPress <= 1.1.1 - Authenticated (Subscriber+) Blind Server-Side Request ForgeryEPSS 0.2%CVE-2025-13999HIGHHTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticated Server-Side Request ForgeryEPSS 0.2%CVE-2020-14328—A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could EPSS 0.2%CVE-2024-13360MEDIUMAI Power: Complete AI Pack <= 1.8.96 - Authenticated (Subscriber+) Server-Side Request ForgeryEPSS 0.2%CVE-2026-75053MEDIUMIn JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpointEPSS 0.2%