CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

801
Total CVEs
165
Critical
303
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
118
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Gitlab 7
5 Sap 6
6 Craftcms 5
7 Agpt 5
8 Maccms 5
9 Progress 4
10 Janeczku 4

All Server-Side Request Forgery (SSRF) CVEs (801)

CVE-2025-59503
10.0

This critical Server-Side Request Forgery (SSRF) vulnerability in Azure Compute Gallery allows unauthorized attackers to make internal network request...

Oct 23, 2025
CVE-2025-54122
10.0

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Manager accounting software allows attackers to make arbitrary HTTP requests fr...

Jul 21, 2025
CVE-2025-2828
10.0

This Server-Side Request Forgery (SSRF) vulnerability in langchain-community's RequestsToolkit allows attackers to make unauthorized requests to inter...

Jun 23, 2025
CVE-2024-42467
10.0

The openHAB CometVisu add-on prior to version 4.2.1 has an unauthenticated proxy endpoint that can be exploited as Server-Side Request Forgery (SSRF) ...

Aug 12, 2024
CVE-2023-43654
10.0

TorchServe versions 0.1.0 to 0.8.1 have a critical vulnerability where the default configuration lacks proper input validation, allowing attackers to ...

Sep 28, 2023
CVE-2023-39967
10.0

CVE-2023-39967 is a server-side request forgery (SSRF) vulnerability in WireMock Studio that allows attackers to make arbitrary HTTP requests from the...

Sep 6, 2023
CVE-2023-3432
10.0

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in PlantUML versions prior to 1.2023.9. Attackers can exploit this vulnerability...

Jun 27, 2023
CVE-2021-27329
10.0

CVE-2021-27329 is a Server-Side Request Forgery (SSRF) vulnerability in Friendica's parse_url parameter that allows attackers to make DNS lookups or H...

Feb 18, 2021
CVE-2025-64663
9.9

This CVE describes an elevation of privilege vulnerability in Microsoft's Custom Question Answering service. Attackers can exploit this to gain unauth...

Dec 18, 2025
CVE-2025-54381
9.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in BentoML's file upload system. Unauthenticated attackers can force the server ...

Jul 29, 2025
CVE-2025-29972
9.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Azure services that allows an authorized attacker to make the server send req...

May 8, 2025
CVE-2024-6784
9.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ABB industrial control system products that allows attackers to make the serv...

Dec 5, 2024
CVE-2023-3744
9.9

CVE-2023-3744 is a Server-Side Request Forgery vulnerability in SLims 9.6.0 that allows authenticated attackers to make requests to internal services ...

Oct 2, 2023
CVE-2022-0939
9.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Calibre-Web, an open-source web application for managing eBook collections. A...

Apr 4, 2022
CVE-2021-33690
9.9

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Development Infrastructure Component Build Service that allows ...

Sep 15, 2021
CVE-2026-26339
9.8

CVE-2026-26339 is a critical argument injection vulnerability in Hyland Alfresco Transformation Service that allows unauthenticated attackers to execu...

Feb 19, 2026
CVE-2025-11242
9.8

This Server-Side Request Forgery (SSRF) vulnerability in Teknolist Okulistik allows attackers to make unauthorized requests from the vulnerable server...

Feb 10, 2026
CVE-2025-62615
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in AutoGPT's RSSFeedBlock component. Attackers can exploit unfiltered URL inputs...

Feb 4, 2026
CVE-2025-62616
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in AutoGPT's SendDiscordFileBlock component. Attackers can exploit unfiltered UR...

Feb 4, 2026
CVE-2025-66405
9.8

CVE-2025-66405 is a Server-Side Request Forgery (SSRF) vulnerability in Portkey.ai Gateway versions before 1.14.0. Attackers can manipulate the x-port...

Dec 1, 2025
CVE-2025-58045
9.8

This vulnerability in Dataease allows attackers to exploit the DB2 JDBC connection string to trigger server-side request forgery (SSRF) attacks. In Da...

Sep 15, 2025
CVE-2024-9408
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Eclipse GlassFish application server. Attackers can exploit specific endpoint...

Jul 16, 2025
CVE-2025-45872
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in zrlog v3.1.5 that allows attackers to make arbitrary HTTP requests from the v...

Jul 1, 2025
CVE-2024-48590
9.8

Inflectra SpiraTeam 7.2.00 contains a Server-Side Request Forgery (SSRF) vulnerability in the NewsReaderService that allows attackers to make the serv...

Mar 20, 2025
CVE-2025-27655
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) that allows attackers to make unauthoriz...

Mar 5, 2025
CVE-2025-27651
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) that allows attackers to make unauthoriz...

Mar 5, 2025
CVE-2025-22952
EPSS 35% 9.8

CVE-2025-22952 is a Server-Side Request Forgery (SSRF) vulnerability in elestio memos v0.23.0 that allows attackers to make unauthorized requests from...

Feb 27, 2025
CVE-2024-48874
9.8

This vulnerability allows attackers to force Ruijie Reyee OS proxy servers to make arbitrary requests, potentially accessing internal Ruijie services ...

Dec 6, 2024
CVE-2024-47167
9.8

This Server-Side Request Forgery (SSRF) vulnerability in Gradio allows attackers to force the server to make HTTP requests to arbitrary URLs, potentia...

Oct 10, 2024
CVE-2024-47222
9.8

This vulnerability in Cloud MyOffice SDK Collaborative Editing Server allows Server-Side Request Forgery (SSRF) through manipulation of MS-WOPI protoc...

Sep 23, 2024
CVE-2024-38183
9.8

An improper access control vulnerability in GroupMe allows unauthenticated attackers to elevate privileges remotely. This affects GroupMe users and po...

Sep 17, 2024
CVE-2024-44677
9.8

CVE-2024-44677 is a critical Server-Side Request Forgery (SSRF) vulnerability in eladmin v2.7 and earlier that allows authenticated attackers to make ...

Sep 10, 2024
CVE-2024-44721
9.8

SeaCMS v13.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /admin_reslib.php file via the url parameter. This allows attackers to...

Sep 9, 2024
CVE-2024-41570
9.8

CVE-2024-41570 is an unauthenticated Server-Side Request Forgery vulnerability in Havoc 2 C2 framework's demon callback handling. It allows attackers ...

Aug 12, 2024
CVE-2024-29319
9.8

Volmarg Personal Management System 1.4.64 contains a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to make the server send HT...

Jul 5, 2024
CVE-2024-5822
9.8

This SSRF vulnerability in ChuanhuChatGPT's upload processing interface allows attackers to make the server send requests to internal or external reso...

Jun 27, 2024
CVE-2023-46295
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary code on Teledyne FLIR M300 thermal camera systems by sending a malic...

May 1, 2024
CVE-2024-27565
9.8

This Server-Side Request Forgery (SSRF) vulnerability in the ChatGPT-wechat-personal project allows attackers to force the application to make arbitra...

Mar 5, 2024
CVE-2024-23761
9.8

CVE-2024-23761 is a Server-Side Template Injection vulnerability in Gambio e-commerce software that allows attackers to execute arbitrary code by mani...

Feb 12, 2024
CVE-2023-42282
9.8

The ip package for Node.js before version 1.1.9 incorrectly categorizes certain IP address formats (like 0x7f.1) as globally routable via the isPublic...

Feb 8, 2024
CVE-2023-51467
9.8

CVE-2023-51467 is an authentication bypass vulnerability in Apache OFBiz that allows attackers to circumvent authentication mechanisms and remotely ex...

Dec 26, 2023
CVE-2023-6974
9.8

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MLflow that allows attackers to make unauthorized requests to internal HTTP(s...

Dec 20, 2023
CVE-2023-48910
9.8

Microcks up to version 1.17.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /jobs and /artifact/download components. Attackers ca...

Dec 4, 2023
CVE-2023-46480
9.8

A Server-Side Request Forgery (SSRF) vulnerability in OwnCast v0.1.1 allows remote attackers to execute arbitrary code and access sensitive informatio...

Nov 27, 2023
CVE-2023-5974
9.8

The WPB Show Core WordPress plugin through version 2.2 contains a server-side request forgery (SSRF) vulnerability in the 'path' parameter. This allow...

Nov 27, 2023
CVE-2023-43982
9.8

This SSRF vulnerability in Bon Presta boninstagramcarousel allows attackers to make the vulnerable server send HTTP requests to arbitrary internal or ...

Nov 3, 2023
CVE-2023-5572
9.8

This Server-Side Request Forgery (SSRF) vulnerability in Vrite allows attackers to make unauthorized requests from the server to internal or external ...

Oct 13, 2023
CVE-2023-41449
9.8

CVE-2023-41449 is a critical remote code execution vulnerability in phpkobo AjaxNewsTicker v1.0.5 that allows attackers to execute arbitrary code via ...

Sep 27, 2023
CVE-2023-35175
9.8

HP LaserJet Pro printers are vulnerable to Server-Side Request Forgery (SSRF) that could allow attackers to execute arbitrary code or gain elevated pr...

Jun 30, 2023
CVE-2018-17452
9.8

This Server-Side Request Forgery (SSRF) vulnerability in GitLab allows attackers to make the server send requests to internal network services via loo...

Apr 15, 2023

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 801 CVEs classified as CWE-918, with 165 rated critical and 303 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free