Falhas do tipo CWE-918

3.086 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2026-44502MEDIUMBugsink: SSRF bypass in `validate_webhook_url`EPSS 0.4%CVE-2026-4366MEDIUMKeycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloakEPSS 0.4%CVE-2026-13739HIGHServer-Side Request Forgery (SSRF)EPSS 0.4%CVE-2026-15643CRITICALAWS HealthLake MCP Server SSRF via Pagination URLEPSS 0.4%CVE-2026-4964MEDIUMletta-ai letta File URL message_helper.py _convert_message_create_to_message server-side request forgeryEPSS 0.4%CVE-2026-33540HIGHDistribution affected by pull-through cache credential exfiltration via www-authenticate bearer realmEPSS 0.4%CVE-2025-2691HIGHVersions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname thEPSS 0.4%CVE-2026-34504MEDIUMOpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal ProviderEPSS 0.4%CVE-2026-5052MEDIUMVault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNSEPSS 0.4%CVE-2026-48858MEDIUMftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksEPSS 0.4%CVE-2026-92932MEDIUMMISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF When readFile Is DisabledEPSS 0.4%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.4%CVE-2025-13281MEDIUMPortworx Half-Blind SSRF in kube-controller-managerEPSS 0.4%CVE-2026-42184MEDIUMTauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC CommandsEPSS 0.4%CVE-2026-55455MEDIUMAppsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylistEPSS 0.4%CVE-2026-73432MEDIUMStored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookupEPSS 0.4%CVE-2026-53927MEDIUMNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URLEPSS 0.4%CVE-2026-57940LOWHTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in sysEPSS 0.4%CVE-2026-12473HIGHOHIF Viewers DICOM Server-Side request forgeryEPSS 0.4%CVE-2026-68558HIGHWekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)EPSS 0.4%