← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Stripe
1Smokescreen
Jun 17, 2026
Apr 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applicati...Show more
Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional (e.g., external) URLs by way of a deny list. There was an issue in Smokescreen that made it possible to bypass the deny list feature by appending a dot to the end of user-supplied URLs, or by providing input in a different letter case. Recommended to upgrade Smokescreen to version 0.0.3 or later.Show less
2Fedoraproject
Hashicorp
2Consul
Fedora
Jun 17, 2026
Apr 19, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10....Show more
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.Show less
1Villatheme
1Exmage
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs
1Chamilo
1Chamilo Lms
Jun 17, 2026
Apr 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
2Debian
Digium
2Asterisk
Debian Linux
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2...Show more
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.Show less
1Ibm
1Planning Analytics
Jun 17, 2026
Apr 8, 2022
N/A· v4
7.3 HIGH· v3
6.5 MEDIUM· v2
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facili...Show more
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.Show less
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys Al...Show more
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.Show less
1Drtrustusa
1Icheck Connect Bp Monitor Bp Testing 118 Firmware
Jul 9, 2026
Apr 7, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Apr 5, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
1Gitlab
1Gitlab
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 where a blind SSRF attack through the repository mirroring feature was possible.Show less
1Janeczku
1Calibre Web
Jun 17, 2026
Apr 4, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
1Janeczku
1Calibre Web
Jun 17, 2026
Apr 4, 2022
N/A· v4
9.9 CRITICAL· v3
7.5 HIGH· v2
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Mar 31, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
1Softwareag
1Mashzone Nextgen
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idssche...Show more
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.Show less
1Sonatype
1Nexus Repository Manager
Jun 17, 2026
Mar 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
1Orckestra
1C1 Cms
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests...Show more
C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The attacker may also truncate arbitrary files to zero size (effectively delete them) leading to denial of service (DoS) or altering application logic. The authenticated user may unknowingly perform the actions by visiting a specially crafted site. Patched in C1 CMS v6.12, no known workarounds exist.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address space were not blocked.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 28, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.
1Hashicorp
1Sentinel
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).