Falhas do tipo CWE-918

3.091 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2023-45705LOWHCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF)EPSS 0.4%CVE-2026-48918MEDIUMJenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.EPSS 0.4%CVE-2023-37230HIGHLoftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.EPSS 0.4%CVE-2026-46717HIGHNezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notificationEPSS 0.4%CVE-2023-37229HIGHLoftware Spectrum before 5.1 allows SSRF.EPSS 0.4%CVE-2025-66405MEDIUMPortkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom HostEPSS 0.4%CVE-2025-55151HIGHStirling-PDF SSRF vulnerability on /api/v1/convert/file/pdfEPSS 0.4%CVE-2026-30953HIGHLinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequestEPSS 0.4%CVE-2023-26459HIGHServer Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.4%CVE-2026-77822HIGHIBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpointEPSS 0.4%CVE-2026-55113HIGHA malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk ApplicatioEPSS 0.4%CVE-2026-69246HIGHGuzzle: Noncanonical host can bypass host-based checksEPSS 0.4%CVE-2026-72598MEDIUMApioo Fusio - Server-Side Request ForgeryEPSS 0.4%CVE-2026-45561MEDIUMRoxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPsEPSS 0.4%CVE-2026-72591HIGHKoito - Authenticated Server-Side Request Forgery via Album Image URL ParameterEPSS 0.4%CVE-2026-29925HIGHInvoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.EPSS 0.4%CVE-2025-8133MEDIUMyanyutao0402 ChanCMS gather.js getArticle server-side request forgeryEPSS 0.4%CVE-2026-91079MEDIUMHuly Platform through 0.7.426 SSRF via Print ServiceEPSS 0.4%CVE-2026-49120MEDIUMMedplum < 5.1.14 SSRF via FHIR Subscription EndpointEPSS 0.4%CVE-2024-31288HIGHWordPress RapidLoad plugin <= 2.2.11 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.4%