← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codiad
1Codiad
Jun 17, 2026
Aug 24, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server requ...Show more
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/market/class.market.php. This could potentially result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."Show less
1Instructure
1Canvas Learning Management Service
Jun 17, 2026
Aug 21, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
1Ftp Srv Project
1Ftp Srv
Jun 17, 2026
Aug 17, 2020
N/A· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT co...Show more
ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version2 2.19.6, 3.1.2, and 4.3.4. More information can be found on the linked advisory.Show less
1Phpbb
1Phpbb
Jun 17, 2026
Aug 17, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
1Redhat
1Cloudforms Management Engine
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not nor...Show more
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.Show less
1Gitlab
1Runner
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
1Prometheus
1Blackbox Exporter
Jun 17, 2026
Aug 9, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability
1Jetbrains
1Youtrack
Jun 17, 2026
Aug 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
1Jetbrains
1Youtrack
Jun 17, 2026
Aug 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
1Shopware
1Shopware
Jun 17, 2026
Jul 28, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shop...Show more
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.Show less
1Bitwarden
1Server
Jun 17, 2026
Jul 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
1Transloadit
1Uppy
Jun 17, 2026
Jul 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal syste...Show more
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.Show less
1Linuxfoundation
1Harbor
Jun 17, 2026
Jul 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an at...Show more
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.Show less
1Atlassian
1Bitbucket
Jun 17, 2026
Jul 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.
1Monstaftp
1Monsta Ftp
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arb...Show more
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.Show less
1Atlassian
1Jira
Jun 17, 2026
Jul 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a l...Show more
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.Show less
1Bitrix24
1Bitrix24
Jun 17, 2026
Jun 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" conten...Show more
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Jun 19, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.