Server-Side Request Forgery

CWE-918 · 30 records · 26 with a public proof-of-concept

Records the NVD classes as Server-Side Request Forgery (CWE-918), highest CVSS first.

  1. HIGH 8.8CVE-2026-15307public PoC

    An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lo

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.6CVE-2026-71270public PoC

    Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf).

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.5CVE-2026-71280public PoC

    go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks).

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.5CVE-2026-71271public PoC

    Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in internal/ht

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.7CVE-2026-70479public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidate

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-66901public PoC

    Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked a

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-47618public PoC

    NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.5CVE-2026-47617public PoC

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.5CVE-2026-47616public PoC

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 7.5CVE-2026-47615public PoC

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 7.5CVE-2026-47614public PoC

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 7.5CVE-2026-47613public PoC

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to informa

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 7.1CVE-2026-71211public PoC

    MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/serve

    AI risk analysis on Exploit-DB.ai →

  14. HIGH 7.1CVE-2026-70485public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without

    AI risk analysis on Exploit-DB.ai →

  15. MEDIUM 6.8CVE-2026-70620public PoC

    Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without sche

    AI risk analysis on Exploit-DB.ai →

  16. MEDIUM 6.8CVE-2026-14939

    The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance

    AI risk analysis on Exploit-DB.ai →

  17. MEDIUM 6.5CVE-2026-71244public PoC

    Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a diff

    AI risk analysis on Exploit-DB.ai →

  18. MEDIUM 6.5CVE-2026-71208public PoC

    KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specified Kubernetes API endp

    AI risk analysis on Exploit-DB.ai →

  19. MEDIUM 6.3CVE-2026-54020public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname aga

    AI risk analysis on Exploit-DB.ai →

  20. MEDIUM 6.3CVE-2026-18775public PoC

    A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The a

    AI risk analysis on Exploit-DB.ai →

  21. MEDIUM 6.3CVE-2026-18774public PoC

    A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack m

    AI risk analysis on Exploit-DB.ai →

  22. MEDIUM 5.8CVE-2026-10526

    The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services

    AI risk analysis on Exploit-DB.ai →

  23. MEDIUM 5.4CVE-2026-70367

    A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”)

    AI risk analysis on Exploit-DB.ai →

  24. MEDIUM 5.3CVE-2026-16536

    The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases,

    AI risk analysis on Exploit-DB.ai →

  25. MEDIUM 4.7CVE-2026-18856public PoC

    A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename

    AI risk analysis on Exploit-DB.ai →

  26. MEDIUM 4.3CVE-2026-71250public PoC

    Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated user (with webhooks enabled, which is off b

    AI risk analysis on Exploit-DB.ai →

  27. MEDIUM 4.3CVE-2026-71246public PoC

    Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https

    AI risk analysis on Exploit-DB.ai →

  28. MEDIUM 4.1CVE-2026-70591public PoC

    Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could

    AI risk analysis on Exploit-DB.ai →

  29. MEDIUM 4.1CVE-2026-70480public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser without a restricted resource

    AI risk analysis on Exploit-DB.ai →

  30. UNSCOREDCVE-2026-69257public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before chec

    AI risk analysis on Exploit-DB.ai →