CWE-918: Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

803
Total CVEs
165
Critical
305
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
118
2025
340
2024
157
2023
60
2022
53

Top Affected Vendors

1 Microsoft 16
2 Apache 16
3 Ibm 9
4 Gitlab 7
5 Sap 6
6 Craftcms 5
7 Agpt 5
8 Maccms 5
9 Langchain 4
10 Progress 4

All Server-Side Request Forgery (SSRF) CVEs (803)

CVE-2024-23838
7.5

This vulnerability in TrueLayer.NET SDK allows attackers to manipulate HttpClient destination URLs, potentially redirecting API requests to malicious ...

Jan 30, 2024
CVE-2024-21642
7.5

CVE-2024-21642 is a server-side request forgery (SSRF) vulnerability in D-Tale versions before 3.9.0 that allows attackers to access files on the serv...

Jan 5, 2024
CVE-2023-7078
7.5

CVE-2023-7078 is a server-side request forgery (SSRF) vulnerability in Miniflare's development server that allows attackers to send arbitrary HTTP and...

Dec 29, 2023
CVE-2023-49799
7.5

This vulnerability in nuxt-api-party allows attackers to bypass URL validation by adding leading whitespace before absolute URLs, enabling Server-Side...

Dec 9, 2023
CVE-2023-45966
7.5

CVE-2023-45966 is a Blind Server-Side Request Forgery vulnerability in umputun remark42 comment server versions 1.12.1 and earlier. It allows attacker...

Oct 23, 2023
CVE-2023-46303
7.5

This vulnerability in calibre's HTML conversion plugin allows Server-Side Request Forgery (SSRF) by default, enabling attackers to access resources ou...

Oct 22, 2023
CVE-2023-42439
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in GeoNode versions 3.2.0 through 4.1.3 that bypasses existing URL whitelist con...

Sep 15, 2023
CVE-2023-41937
7.5

This vulnerability in Jenkins Bitbucket Plugin allows attackers to steal Bitbucket credentials stored in Jenkins by sending malicious webhook payloads...

Sep 6, 2023
CVE-2023-40017
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in GeoNode's proxy endpoint. Attackers can exploit the `/proxy/?url=` endpoint t...

Aug 24, 2023
CVE-2023-37290
7.5

This vulnerability in InfoDoc Document On-line Submission and Approval System allows unauthenticated attackers to perform Server-Side Request Forgery ...

Jul 20, 2023
CVE-2023-35133
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Moodle's cURL blocked hosts list logic. The flaw allows attackers to bypass I...

Jun 22, 2023
CVE-2023-26735
7.5

CVE-2023-26735 is an access control vulnerability in blackbox_exporter v0.23.0 that allows attackers to probe internal network ports and services thro...

Apr 26, 2023
CVE-2023-2140
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in DELMIA Apriso manufacturing software. Unauthenticated attackers can force the...

Apr 21, 2023
CVE-2023-27159
7.5

Appwrite versions up to 1.2.1 contain a Server-Side Request Forgery (SSRF) vulnerability in the /v1/avatars/favicon endpoint. Attackers can send craft...

Mar 31, 2023
CVE-2021-36396
7.5

This vulnerability in Moodle allows attackers to bypass cURL security restrictions through insufficient redirect handling, enabling blind Server-Side ...

Mar 6, 2023
CVE-2022-4492
7.5

CVE-2022-4492 is a server certificate validation bypass vulnerability in Undertow HTTP client. It allows attackers to perform man-in-the-middle attack...

Feb 23, 2023
CVE-2022-2339
7.5

CVE-2022-2339 is a Server-Side Request Forgery (SSRF) vulnerability in NocoDB that allows attackers to make requests to internal network resources fro...

Jul 7, 2022
CVE-2022-28997
7.5

CVE-2022-28997 is a Server-Side Request Forgery (SSRF) vulnerability in CSZCMS v1.3.0 that allows attackers to make the server request internal resour...

May 23, 2022
CVE-2022-1767
7.5

This Server-Side Request Forgery (SSRF) vulnerability in draw.io allows attackers to make unauthorized requests from the server to internal systems. I...

May 18, 2022
CVE-2022-1711
7.5

This Server-Side Request Forgery (SSRF) vulnerability in draw.io allows attackers to make unauthorized requests from the server to internal systems. I...

May 17, 2022
CVE-2022-1713
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint of draw.io diagramming software. Attackers can exploit th...

May 16, 2022
CVE-2022-29847
7.5

This vulnerability allows unauthenticated attackers to invoke an API transaction that relays encrypted WhatsUp Gold user credentials to arbitrary host...

May 11, 2022
CVE-2021-40822
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in GeoServer that allows attackers to make arbitrary HTTP requests from the vuln...

May 2, 2022
CVE-2022-25850
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the hoppscotch/proxyscotch package when interceptor mode is set to proxy. It ...

May 1, 2022
CVE-2021-44139
7.5

CVE-2021-44139 is a Server-Side Request Forgery (SSRF) vulnerability in Sentinel 1.8.2 that allows attackers to make unauthorized requests from the vu...

Mar 23, 2022
CVE-2021-45968
7.5

This vulnerability allows Server-Side Request Forgery (SSRF) attacks against the XMPP Server component in Pascom Cloud Phone System and other JIve pla...

Mar 18, 2022
CVE-2022-24980
7.5

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks against TYPO3 installations using vulnerable...

Feb 19, 2022
CVE-2021-45325
7.5

This Server-Side Request Forgery (SSRF) vulnerability in Gitea before version 1.7.0 allows attackers to make unauthorized requests from the Gitea serv...

Feb 8, 2022
CVE-2022-23206
7.5

This vulnerability allows unprivileged users to perform port scanning on internal networks via Apache Traffic Control Traffic Ops. Attackers can send ...

Feb 6, 2022
CVE-2022-0132
7.5

CVE-2022-0132 is a Server-Side Request Forgery (SSRF) vulnerability in PeerTube that allows attackers to make the server send HTTP requests to arbitra...

Jan 10, 2022
CVE-2021-27738
7.5

This vulnerability allows unauthenticated attackers to manipulate Apache Kylin's streaming cube management and replica sets via unprotected REST API e...

Jan 6, 2022
CVE-2021-22056
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in VMware Workspace ONE Access and Identity Manager products. It allows attacker...

Dec 20, 2021
CVE-2021-43296
7.5

This vulnerability allows attackers to perform Server-Side Request Forgery (SSRF) attacks through the ActionExecutor component in Zoho ManageEngine Su...

Nov 30, 2021
CVE-2021-22970
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Concrete CMS that allows authenticated users to make requests to internal net...

Nov 19, 2021
CVE-2020-20341
7.5

YzmCMS v5.5 contains a server-side request forgery (SSRF) vulnerability in the grab_image() function that allows attackers to make arbitrary HTTP requ...

Sep 1, 2021
CVE-2021-22027
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the vRealize Operations Manager API. Unauthenticated attackers with network a...

Aug 30, 2021
CVE-2020-14160
7.5

This SSRF vulnerability in Gotenberg allows attackers to read local files or access internal network resources through the remote URL to PDF conversio...

Aug 26, 2021
CVE-2020-20582
7.5

This SSRF vulnerability in MipCMS allows attackers to make the server send unauthorized requests to internal systems. Attackers can potentially access...

Jul 8, 2021
CVE-2020-24149
7.5

This CVE describes a server-side request forgery (SSRF) vulnerability in the Podcast Importer SecondLine WordPress plugin. Attackers can exploit this ...

Jul 7, 2021
CVE-2021-33571
7.5

This vulnerability allows attackers to bypass IP-based access controls in Django applications by using leading zeros in IPv4 addresses (octal notation...

Jun 8, 2021
CVE-2020-35970
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in YzmCMS 5.8's background collection management feature. It allows authenticate...

Jun 3, 2021
CVE-2021-33511
7.5

CVE-2021-33511 is a Server-Side Request Forgery (SSRF) vulnerability in Plone CMS that allows attackers to make unauthorized requests from the server ...

May 21, 2021
CVE-2021-31910
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in JetBrains TeamCity that allows attackers to make unauthorized requests from t...

May 11, 2021
CVE-2020-22002
7.5

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks against Inim Electronics Smartliving SmartLA...

Apr 29, 2021
CVE-2021-24150
7.5

This vulnerability allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks through the LikeBtn WordPress plugin. Attack...

Apr 5, 2021
CVE-2020-19613
7.5

This Server-Side Request Forgery (SSRF) vulnerability in FlyCMS allows attackers to make the server send HTTP requests to arbitrary internal or extern...

Apr 1, 2021
CVE-2020-35558
7.5

This vulnerability is a Server-Side Request Forgery (SSRF) in the MySQL access check of MB connect line products, allowing attackers to scan internal ...

Feb 16, 2021
CVE-2020-35667
7.5

CVE-2020-35667 is a Server-Side Request Forgery (SSRF) vulnerability in JetBrains TeamCity Plugin that allows attackers to make unauthorized requests ...

Feb 3, 2021
CVE-2020-23776
7.5

This is a Server-Side Request Forgery (SSRF) vulnerability in Winmail 6.5 that allows attackers to manipulate the server into making unauthorized HTTP...

Jan 26, 2021
CVE-2025-64511
7.4

This vulnerability in MaxKB allows authenticated users to bypass sandbox restrictions and execute Python code that can access internal network service...

Nov 13, 2025

About Server-Side Request Forgery (SSRF) (CWE-918)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Our database tracks 803 CVEs classified as CWE-918, with 165 rated critical and 305 rated high severity. The average CVSS score for Server-Side Request Forgery (SSRF) vulnerabilities is 7.2.

External reference: View CWE-918 on MITRE CWE →

Monitor Server-Side Request Forgery (SSRF) Vulnerabilities

Get alerted when new Server-Side Request Forgery (SSRF) CVEs affect your infrastructure.

Start Monitoring Free