CWE-918
MITRE ↗Server-Side Request Forgery (SSRF)
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests t
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attac
An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix
WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/previe
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve
Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in
The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Serve
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, valid
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a par
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the v
Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-su
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook dat
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe
Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili
NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al
IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from
SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated a
Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR
go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insuffici
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a re
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF
Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter th
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil
Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execu
Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (age
Frequently Asked Questions
What is CWE-918?
CWE-918 (Server-Side Request Forgery (SSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-918?
There are 3,755 CVE records associated with CWE-918 in our database. Of these, 428 are critical severity, 1157 are high severity, and 1478 are medium severity.
How can I protect against CWE-918 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-918 using AI-powered security agents.
Detect CWE-918 Vulnerabilities
CyberStrike's AI agents automatically detect server-side request forgery (ssrf) vulnerabilities across your infrastructure.
Get Started