Falhas do tipo CWE-918

3.105 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2026-12767MEDIUMLangflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesEPSS 0.2%CVE-2026-12765MEDIUMLangflow OSS is affected by server-side request forgery due to missing URL validation in flow componentsEPSS 0.2%CVE-2026-25428MEDIUMWordPress TS Poll plugin <= 2.5.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-47483MEDIUMWordPress Easy Replace Image plugin <= 3.5.0 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2025-30964MEDIUMWordPress Photography theme < 7.7.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-12388MEDIUMB Carousel Block – Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request ForgeryEPSS 0.2%CVE-2024-45843LOWWeak SSRF FilteringEPSS 0.2%CVE-2024-55089MEDIUMRhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may coEPSS 0.2%CVE-2024-56471MEDIUMIBM Aspera Shares Server-Side Request ForgeryEPSS 0.2%CVE-2025-47664MEDIUMWordPress WP Pipes <= 1.4.2 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2024-56470MEDIUMIBM Aspera Shares Server-Side Request ForgeryEPSS 0.2%CVE-2026-53945MEDIUMGhost: Server-side request forgery via DNS rebinding in external request handlingEPSS 0.2%CVE-2023-31456MEDIUMThere is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitEPSS 0.2%CVE-2025-49374MEDIUMWordPress Captcha.eu plugin <= 1.0.61 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-43747MEDIUMA server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation oEPSS 0.2%CVE-2026-55599MEDIUMphpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information AccessEPSS 0.2%CVE-2025-58962MEDIUMWordPress Publitio Plugin <= 2.2.1 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-54353HIGHBudibase: Potential SSRF DNS rebinding bypass in outbound fetch validationEPSS 0.2%CVE-2025-46511MEDIUMWordPress BeerXML Shortcode plugin <= 0.7.1 - Server Side Request Forgery (SSRF) VulnerabilityEPSS 0.2%CVE-2026-21887HIGHOpenCTI has a Semi-Blind SSRF via Unvalidated External URL in Data Ingestion FeatureEPSS 0.2%