Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: ssrf Clear
ID Title
CVE-2026-4328 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-4328)
SSRF in wordpress (CVE-2026-4328). Risk of unauthorized operations or information disclosure.
CVE-2026-55229 SSRF (Server-Side Request Forgery) in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229)
SSRF in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229). Confidential information can be exposed externally. Exploitable via `GET /secretendpoint`. Mitigation: upgrade to `8.34.0` or later.
CVE-2026-48764 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48764)
SSRF in ssrf (CVE-2026-48764). Confidential information can be exposed externally.
CVE-2026-48814 Vulnerability in network-ai (CVE-2026-48814)
vulnerability in network-ai (CVE-2026-48814). Confidential information can be exposed externally. Exploitable via `POST /mcp`. Mitigation: upgrade to `5.7.2` or later.
CVE-2026-55471 XXE (XML External Entity) in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471). Confidential information can be exposed externally. Exploitable via `GET /evil-fhir-xslt-ssrf.dtd`. Mitigation: upgrade to `6.9.10` or later.
CVE-2026-54018 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54018)
SSRF in open-webui (CVE-2026-54018). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54017 Path Traversal in open-webui (CVE-2026-54017)
path traversal in open-webui (CVE-2026-54017). Confidential information can be exposed externally. Exploitable via `GET /api/v1/terminals/server1/..`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-53755 SSRF (Server-Side Request Forgery) in crawl4ai (CVE-2026-53755)
SSRF in crawl4ai (CVE-2026-53755). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.9` or later.
CVE-2026-53754 SSRF (Server-Side Request Forgery) in crawl4ai (CVE-2026-53754)
SSRF in crawl4ai (CVE-2026-53754). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.8` or later.
CVE-2025-60175 Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
CVE-2026-50887 SSRF (Server-Side Request Forgery) in shlinkio/shlink (CVE-2026-50887)
SSRF in shlinkio/shlink (CVE-2026-50887). Confidential information can be exposed externally.
CVE-2026-50888 SSRF (Server-Side Request Forgery) in koillection/koillection (CVE-2026-50888)
SSRF in koillection/koillection (CVE-2026-50888). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.4` or later.
CVE-2026-48818 SSRF (Server-Side Request Forgery) in starlette (CVE-2026-48818)
SSRF in starlette (CVE-2026-48818). Confidential information can be exposed externally. Exploitable via ``StaticFiles``. Mitigation: upgrade to `1.1.0` or later.
CVE-2026-50168 Vulnerability in @angular/platform-server (CVE-2026-50168)
vulnerability in @angular/platform-server (CVE-2026-50168). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `21.2.15` or later.
CVE-2026-53607 SSRF (Server-Side Request Forgery) in apostrophe (CVE-2026-53607)
SSRF in apostrophe (CVE-2026-53607). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `4.31.0` or later.
CVE-2026-50552 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-50552)
SSRF in phanan/koel (CVE-2026-50552). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/radio/stations`. Mitigation: upgrade to `9.7.1` or later.
CVE-2025-58175 Vulnerability in org.geoserver.web:gs-web-app (CVE-2025-58175)
vulnerability in org.geoserver.web:gs-web-app (CVE-2025-58175). Confidential information can be exposed externally. Exploitable via ``ENTITY_RESOLUTION_ALLOWLIST``. Mitigation: upgrade to `2.27.3` or later.
CVE-2026-53782 @steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
@steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
CVE-2026-47170 Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HT...
Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HTTP requests to internal services via the uploadFromUrl endpoint. This allows internal port scanning,...
CVE-2026-46697 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-46697)
SSRF in wordpress (CVE-2026-46697). Confidential information can be exposed externally.
CVE-2026-3341 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-3341)
SSRF in ssrf (CVE-2026-3341). Risk of unauthorized operations or information disclosure.
CVE-2026-50131 SSRF (Server-Side Request Forgery) in @fedify/fedify (CVE-2026-50131)
SSRF in @fedify/fedify (CVE-2026-50131). Confidential information can be exposed externally. Mitigation: upgrade to `2.2.4` or later.
CVE-2026-48858 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48858)
SSRF in ssrf (CVE-2026-48858). Risk of unauthorized operations or information disclosure.
CVE-2026-48051 SSRF (Server-Side Request Forgery) in @papra/webhooks (CVE-2026-48051)
SSRF in @papra/webhooks (CVE-2026-48051). Risk of unauthorized operations or information disclosure. Exploitable via `POST /redirect`. Mitigation: upgrade to `0.3.3` or later.
CVE-2026-47938 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47938)
SSRF in ssrf (CVE-2026-47938). Successful exploitation can lead to full system takeover.
CVE-2026-45504 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45504)
SSRF in ssrf (CVE-2026-45504). Successful exploitation can lead to full system takeover.
CVE-2026-45501 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45501)
SSRF in ssrf (CVE-2026-45501). Confidential information can be exposed externally.
CVE-2026-45502 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45502)
SSRF in ssrf (CVE-2026-45502). Risk of unauthorized operations or information disclosure.
CVE-2026-45503 Vulnerability in ssrf (CVE-2026-45503)
vulnerability in ssrf (CVE-2026-45503). Confidential information can be exposed externally.
CVE-2026-41854 SSRF (Server-Side Request Forgery) in org.springframework:spring-web (CVE-2026-41854)
SSRF in org.springframework:spring-web (CVE-2026-41854). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.19` or later.
CVE-2026-47719 SSRF (Server-Side Request Forgery) in fuxa-server (CVE-2026-47719)
SSRF in fuxa-server (CVE-2026-47719). Confidential information can be exposed externally. Exploitable via ``property.address``.
CVE-2026-11424 Information Disclosure in ssrf (CVE-2026-11424)
vulnerability in ssrf (CVE-2026-11424). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
CVE-2026-47684 SSRF (Server-Side Request Forgery) in @sync-in/server (CVE-2026-47684)
SSRF in @sync-in/server (CVE-2026-47684). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
CVE-2026-11346 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-11346)
SSRF in ssrf (CVE-2026-11346). Risk of unauthorized operations or information disclosure.
CVE-2026-48013 SSRF (Server-Side Request Forgery) in shopware/core (CVE-2026-48013)
SSRF in shopware/core (CVE-2026-48013). Risk of unauthorized operations or information disclosure. Exploitable via ``uploadFromURL``. Mitigation: upgrade to `6.7.10.1` or later.
CVE-2026-43986 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-43986)
SSRF in ssrf (CVE-2026-43986). Confidential information can be exposed externally. Exploitable via ``image_hash_lookup``.
CVE-2026-10771 A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate...
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate...
CVE-2026-44023 Path Traversal in docling-core (CVE-2026-44023)
path traversal in docling-core (CVE-2026-44023). Confidential information can be exposed externally. Mitigation: upgrade to `2.74.1` or later.
CVE-2026-44020 XXE (XML External Entity) in docling (CVE-2026-44020)
vulnerability in docling (CVE-2026-44020). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.74.0` or later.
CVE-2026-44016 Code Injection in docling (CVE-2026-44016)
code injection in docling (CVE-2026-44016). Confidential information can be exposed externally. Exploitable via ``enable_remote_fetch``. Mitigation: upgrade to `2.91.0` or later.
CVE-2026-26379 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-26379)
SSRF in ssrf (CVE-2026-26379). Risk of unauthorized operations or information disclosure.
CVE-2026-20230 KEV [KEV] SSRF (Server-Side Request Forgery) in Cisco ssrf (CVE-2026-20230)
SSRF in Cisco ssrf (CVE-2026-20230). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
CVE-2026-49120 Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription...
Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription...
CVE-2026-8993 Vulnerability in ssrf (CVE-2026-8993)
vulnerability in ssrf (CVE-2026-8993). Confidential information can be exposed externally.
CVE-2026-49328 SSRF (Server-Side Request Forgery) in org.apache.fesod:fesod-sheet (CVE-2026-49328)
SSRF in org.apache.fesod:fesod-sheet (CVE-2026-49328). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.2-incubating` or later.
CVE-2026-10517 SSRF (Server-Side Request Forgery) in github.com/quay/claircore (CVE-2026-10517)
SSRF in github.com/quay/claircore (CVE-2026-10517). Risk of unauthorized operations or information disclosure.
CVE-2026-47390 SSRF (Server-Side Request Forgery) in praisonaiagents (CVE-2026-47390)
SSRF in praisonaiagents (CVE-2026-47390). Confidential information can be exposed externally. Exploitable via ``spider_tools``. Mitigation: upgrade to `1.6.40` or later.
CVE-2026-47268 SSRF (Server-Side Request Forgery) in github.com/nezhahq/nezha (CVE-2026-47268)
SSRF in github.com/nezhahq/nezha (CVE-2026-47268). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/ddns`. Mitigation: upgrade to `2.0.10` or later.
CVE-2026-47695 SSRF (Server-Side Request Forgery) in cc.tweaked:cc-tweaked-1.21-core (CVE-2026-47695)
SSRF in cc.tweaked:cc-tweaked-1.21-core (CVE-2026-47695). Risk of unauthorized operations or information disclosure. Exploitable via ``http.request``. Mitigation: upgrade to `1.119.0` or later.
CVE-2026-44285 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →