CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did
Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request a
Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request
A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using p
The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1
DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fe
Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{I
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below
The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, whic
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url
Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U
Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application valid
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible t
AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote
Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i
Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png en
Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to ca
Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthe
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTM
Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalid
BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, wh
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal netw
Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools incl
A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown funct
A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake
A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the
The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in
Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Fo
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started