Falhas do tipo CWE-918

3.087 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2026-12473HIGHOHIF Viewers DICOM Server-Side request forgeryEPSS 0.4%CVE-2026-60033MEDIUMJoomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0EPSS 0.4%CVE-2026-68558HIGHWekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)EPSS 0.4%CVE-2026-53930MEDIUMNocoDB: Server-Side Request Forgery via Base Migration URLEPSS 0.4%CVE-2026-91935HIGHFlowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model NodesEPSS 0.4%CVE-2026-53927MEDIUMNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URLEPSS 0.4%CVE-2026-21653HIGHCCure and Victor Application Server - Server Side Request ForgeryEPSS 0.4%CVE-2026-73432MEDIUMStored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookupEPSS 0.4%CVE-2026-44286LOWFastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address ValidationEPSS 0.4%CVE-2026-8081MEDIUMrouter-for-me CLIProxyAPI api_tools.go server-side request forgeryEPSS 0.4%CVE-2026-86590MEDIUMIn Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied EPSS 0.4%CVE-2025-10765MEDIUMSeriaWei ZKEACMS SEOSuggestions ZKEACMS.SEOSuggestions.dll server-side request forgeryEPSS 0.4%CVE-2026-32110HIGHSiYuan has a Full-Read SSRF via /api/network/forwardProxyEPSS 0.4%CVE-2021-47776MEDIUMUmbraco v8.14.1 - 'baseUrl' SSRFEPSS 0.4%CVE-2026-54018HIGHOpen WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP RedirectsEPSS 0.4%CVE-2026-33675MEDIUMVikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network ResourcesEPSS 0.4%CVE-2026-42313HIGHpyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxyEPSS 0.4%CVE-2026-41688HIGHIncomplete fix for CVE-2026-33399: SSRF in WallosEPSS 0.4%CVE-2025-25760HIGHA Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and serviceEPSS 0.4%CVE-2024-13923HIGHOrder Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file FunctionEPSS 0.4%