CWE-918
3,430 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (3,430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle6Business Intelligence Communications Diameter Intelligence HubCommunications Element Manager+3 moreJun 17, 2026 Apr 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SS...Show more |
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503. |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerAug 12, 2026 Mar 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forger...Show more |
1F5 15Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+12 moreJun 17, 2026 Mar 31, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST...Show more |
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime r...Show more |
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage of the logo_uri parameter in the Dynami...Show more |
A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature. |
An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration. |
1Spinetix 6Diva Firmware DsosHmp300 Firmware+3 moreJun 17, 2026 Mar 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1...Show more |
6Apache DebianFedoraproject+3 more17Activemq Banking Enterprise Default ManagementBanking Platform+14 moreJun 17, 2026 Mar 23, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publ...Show more |
6Apache DebianFedoraproject+3 more15Activemq Banking Enterprise Default ManagementBanking Platform+12 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the...Show more |
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network...Show more |
IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247. |
Microsoft Exchange Server Remote Code Execution Vulnerability |
1Mbconnectline 2Mbconnect24 Mymbconnect24Jun 17, 2026 Mar 2, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports. |
1Thecodingmachine 1Gotenberg Jun 17, 2026 Feb 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system fil...Show more |
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. |
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. |
2Apache Fedoraproject2Fedora Xmlgraphics CommonsJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnera...Show more |