Robuta

https://portswigger.net/web-security/ssrf What is SSRF (Server-side request forgery)? Tutorial & Examples | Web Security Academy In this section we explain what server-side request forgery (SSRF) is, and describe some common examples. We also show you how to find and exploit SSRF ... server side request forgerywhat is https://github.com/mybb/mybb/security/advisories/GHSA-qfrj-65mv-h75h Incomplete disallowed remote addresses list SSRF · Advisory · mybb/mybb · GitHub GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects. incompletedisallowedremoteaddresseslist https://advisories.gitlab.com/pypi/mindsdb/CVE-2024-24759/ MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding | GitLab Advisory Database (GLAD) CVE-2024-24759 MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding: DNS rebinding is a method of manipulating resolution of domain names to let... https://advisories.gitlab.com/npm/openclaw/CVE-2026-42430/ OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets... CVE-2026-42430 OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable: Strict browser SSRF bypass in Playwright... https://advisories.gitlab.com/npm/flowise/CVE-2026-41270/ Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox |... CVE-2026-41270 Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox: A Server-Side Request Forgery (SSRF)... https://advisories.gitlab.com/golang/github.com/tencent/weknora/CVE-2026-30858/ WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal Resources |... CVE-2026-30858 WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal Resources: A DNS rebinding vulnerability in the web_fetch... https://advisories.gitlab.com/npm/@novu/api/GHSA-4x48-cgf9-q33f/ Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection | GitLab Advisory... GHSA-4x48-cgf9-q33f Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection: The conditions filter webhook at... https://advisories.gitlab.com/nuget/dotnetnuke.core/CVE-2025-32372/ DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2025-32372 DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF): A bypass has been identified for the previously known vulnerability... server side request forgery https://swisskyrepo.github.io/PayloadsAllTheThings/Server%20Side%20Request%20Forgery/SSRF-Advanced-Exploitation/ SSRF Advanced Exploitation - Payloads All The Things Payloads All The Things, a list of useful payloads and bypasses for Web Application Security all thessrfadvancedexploitationpayloads https://advisories.gitlab.com/maven/org.apache.xmlgraphics/batik-svgbrowser/CVE-2022-38398/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2022-38398 Server-Side Request Forgery (SSRF): Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/composer/craftcms/cms/CVE-2025-68437/ Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation |... server side request forgery https://advisories.gitlab.com/composer/roadiz/documents/CVE-2026-33486/ Roadiz has Server-Side Request Forgery (SSRF) in roadiz/documents | GitLab Advisory Database (GLAD) CVE-2026-33486 Roadiz has Server-Side Request Forgery (SSRF) in roadiz/documents: This vulnerability allows an authenticated attacker to read any file on the... server side request forgery https://advisories.gitlab.com/composer/wp-graphql/wp-graphql/CVE-2023-23684/ WPGraphQL Plugin vulnerable to Server Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2023-23684 WPGraphQL Plugin vulnerable to Server Side Request Forgery (SSRF): Impact Users with capabilities to upload media (editors and above) are... server side request forgery https://advisories.gitlab.com/golang/github.com/gravitational/teleport/GHSA-hw4x-mcx5-9q36/ Withdrawn Advisory: Teleport Proxy and Teleport Agents: SSRF to arbitrary hosts is possible from... GHSA-hw4x-mcx5-9q36 Withdrawn Advisory: Teleport Proxy and Teleport Agents: SSRF to arbitrary hosts is possible from low privileged users: An authenticated... https://advisories.gitlab.com/pypi/litellm/CVE-2024-6587/ LiteLLM Server-Side Request Forgery (SSRF) vulnerability | GitLab Advisory Database (GLAD) CVE-2024-6587 LiteLLM Server-Side Request Forgery (SSRF) vulnerability: A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version... server side request forgerylitellm https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-41060/ WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL | GitLab... CVE-2026-41060 WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL: The isSSRFSafeURL() function in... https://advisories.gitlab.com/golang/github.com/gotenberg/gotenberg/v8/CVE-2026-39383/ Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL | GitLab Advisory Database... CVE-2026-39383 Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL: An unauthenticated attacker with network access to Gotenberg can force... https://advisories.gitlab.com/npm/astro/CVE-2025-59837/ Astro's bypass of image proxy domain validation leads to SSRF and potential XSS | GitLab Advisory... CVE-2025-59837 Astro's bypass of image proxy domain validation leads to SSRF and potential XSS: This is a patch bypass of CVE-2025-58179 in commit 9ecf359. The... https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-41055/ WWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF | GitLab Advisory Database (GLAD) CVE-2026-41055 WWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF: The incomplete SSRF fix in AVideo's LiveLinks proxy adds isSSRFSafeURL() validation... https://advisories.gitlab.com/npm/openclaw/GHSA-c4qg-j8jg-42q5/ OpenClaw: QQBot direct media upload skipped URL SSRF validation | GitLab Advisory Database (GLAD) GHSA-c4qg-j8jg-42q5 OpenClaw: QQBot direct media upload skipped URL SSRF validation: The QQBot direct-upload media path could forward attacker-controlled image... https://advisories.gitlab.com/pypi/crawl4ai/CVE-2025-28197/ Crawl4AI SSRF vulnerability | GitLab Advisory Database (GLAD) ssrfvulnerabilitygitlabadvisorydatabase https://advisories.gitlab.com/npm/openclaw/CVE-2026-34504/ OpenClaw affected by SSRF via unguarded image download in fal provider | GitLab Advisory Database... CVE-2026-34504 OpenClaw affected by SSRF via unguarded image download in fal provider: The fal provider used raw fetches for both provider API traffic and... https://advisories.gitlab.com/golang/github.com/mattermost/mattermost/server/v8/CVE-2025-47700/ Mattermost Server SSRF Vulnerability via the Agents Plugin | GitLab Advisory Database (GLAD) mattermost serverthe agents https://advisories.gitlab.com/npm/openclaw/CVE-2026-43526/ OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes | GitLab... CVE-2026-43526 OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes: QQBot reply media URL handling could trigger SSRF and... https://advisories.gitlab.com/npm/@nocobase/plugin-workflow-request/CVE-2026-40346/ NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins | GitLab Advisory Database... CVE-2026-40346 NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins: NocoBase's workflow HTTP request plugin and custom request action plugin... https://advisories.gitlab.com/composer/magento/community-edition/CVE-2019-7913/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2019-7913 Server-Side Request Forgery (SSRF): A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/npm/flowise/CVE-2026-31829/ Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network... CVE-2026-31829 Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access: Description: Flowise exposes an HTTP... server side request forgery https://advisories.gitlab.com/maven/org.xwiki.contrib.plantuml/macro-plantuml-macro/CVE-2026-42140/ XWiki PlantUML Macro Vulnerable to Server-Side Request Forgery (SSRF) via 'server' parameter |... CVE-2026-42140 XWiki PlantUML Macro Vulnerable to Server-Side Request Forgery (SSRF) via 'server' parameter: The PlantUML Macro is vulnerable to Server-Side... server side request forgery https://advisories.gitlab.com/npm/@frontmcp/adapters/CVE-2026-39885/ mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications |... CVE-2026-39885 mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications: The mcp-from-openapi library uses... https://advisories.gitlab.com/maven/org.apache.hugegraph/hugegraph-hubble/CVE-2024-27347/ Apache HugeGraph-Hubble: SSRF in Hubble connection page | GitLab Advisory Database (GLAD) CVE-2024-27347 Apache HugeGraph-Hubble: SSRF in Hubble connection page: Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble. This issue... apache hugegraphin connectionhubblessrf https://advisories.gitlab.com/npm/mcp-from-openapi/CVE-2026-39885/ mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications |... CVE-2026-39885 mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications: The mcp-from-openapi library uses... https://advisories.gitlab.com/npm/@aborruso/ckan-mcp-server/CVE-2026-33060/ SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks | GitLab Advisory... CVE-2026-33060 SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks: The @aborruso/ckan-mcp-server MCP server provides tools... https://advisories.gitlab.com/npm/flowise/GHSA-2x8m-83vc-6wv4/ Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) | GitLab Advisory Database (GLAD) ssrf protectionflowisebypasstoctou https://cwe.mitre.org/data/definitions/918.html CWE - CWE-918: Server-Side Request Forgery (SSRF) (4.20) Common Weakness Enumeration (CWE) is a list of software weaknesses. server side request forgerycwessrf https://owasp.org/Top10/2021/it/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ A10 Server Side Request Forgery (SSRF) - OWASP Top 10:2021 server side request forgeryssrfowasptop https://advisories.gitlab.com/pypi/pydantic-ai/CVE-2026-25580/ Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling | GitLab Advisory... CVE-2026-25580 Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling: A Server-Side Request Forgery (SSRF) vulnerability exists in... server side request forgery https://advisories.gitlab.com/pypi/weasyprint/CVE-2025-68616/ WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect | GitLab... CVE-2025-68616 WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect: A Server-Side Request Forgery (SSRF) Protection Bypass... server side request forgery https://advisories.gitlab.com/pypi/rembg/CVE-2025-25301/ Rembg allows SSRF via /api/remove | GitLab Advisory Database (GLAD) CVE-2025-25301 Rembg allows SSRF via /api/remove: Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a... via apiallowsssrfremovegitlab https://advisories.gitlab.com/npm/flowise/GHSA-9hrv-gvrv-6gf2/ Flowise Execute Flow function has an SSRF vulnerability | GitLab Advisory Database (GLAD) GHSA-9hrv-gvrv-6gf2 Flowise Execute Flow function has an SSRF vulnerability: The attacker provides an intranet address through the base url field configured in... https://advisories.gitlab.com/npm/hemmelig/CVE-2025-69206/ hemmelig allows SSRF Filter bypass via Secret Request functionality | GitLab Advisory Database... CVE-2025-69206 hemmelig allows SSRF Filter bypass via Secret Request functionality: A Server-Side Request Forgery (SSRF) filter bypass vulnerability exists in... filter bypass https://advisories.gitlab.com/npm/flowise/CVE-2026-41271/ Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains | GitLab Advisory Database (GLAD) CVE-2026-41271 Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains: A Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's... https://advisories.gitlab.com/golang/github.com/quantumnous/new-api/CVE-2026-42339/ QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 | GitLab Advisory Database (GLAD) CVE-2026-42339 QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0: The SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6... https://thehackernews.com/2024/02/recently-disclosed-ssrf-flaw-in-ivanti.html?version=meter+at+null Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass Exploitation A recently disclosed SSRF vulnerability (CVE-2024-21893) in Ivanti Connect Secure and Policy Secure products is now under mass exploitation. recentssrfflawivantivpn https://advisories.gitlab.com/maven/io.github.microcks/microcks/CVE-2023-48910/ Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and... CVE-2023-48910 Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download: Microcks up to version 1.17.1 was... server side request forgery https://advisories.gitlab.com/npm/openclaw/GHSA-3fv3-6p2v-gxwj/ OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths | GitLab Advisory... GHSA-3fv3-6p2v-gxwj OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths: QQ Bot Extension: Missing SSRF Protection on All Media Fetch... https://advisories.gitlab.com/gem/faraday/CVE-2026-25765/ Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url | GitLab... CVE-2026-25765 Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url: Faraday's build_exclusive_url method (in... https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-43884/ AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL() | GitLab... CVE-2026-43884 AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL(): Two endpoints in AVideo call isSSRFSafeURL() to... https://advisories.gitlab.com/golang/gogs.io/gogs/CVE-2018-15192/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2018-15192 Server-Side Request Forgery (SSRF): An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/golang/github.com/t2bot/matrix-media-repo/CVE-2024-52602/ Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation |... CVE-2024-52602 Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation: Matrix Media Repo (MMR) is vulnerable to... server side request forgery https://advisories.gitlab.com/npm/flowise-components/GHSA-9hrv-gvrv-6gf2/ Flowise Execute Flow function has an SSRF vulnerability | GitLab Advisory Database (GLAD) GHSA-9hrv-gvrv-6gf2 Flowise Execute Flow function has an SSRF vulnerability: The attacker provides an intranet address through the base url field configured in... https://advisories.gitlab.com/npm/nossrf/CVE-2025-2691/ nossrf Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2025-2691 nossrf Server-Side Request Forgery (SSRF): Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF),... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/pypi/web3/CVE-2026-40072/ web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling | GitLab Advisory Database (GLAD) CVE-2026-40072 web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling: web3.py implements CCIP Read / OffchainLookup (EIP-3668) by performing HTTP... https://advisories.gitlab.com/npm/openclaw/CVE-2026-43527/ OpenClaw: Browser SSRF policy default allowed private-network navigation | GitLab Advisory Database... CVE-2026-43527 OpenClaw: Browser SSRF policy default allowed private-network navigation: Browser SSRF policy default allowed private-network navigation. https://advisories.gitlab.com/composer/moodle/moodle/CVE-2023-35133/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2023-35133 Server-Side Request Forgery (SSRF): An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk.... server side request forgeryssrfgitlabadvisorydatabase https://securitylab.github.com/advisories/GHSL-2023-061_BlueOcean/ GHSL-2023-061: Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) in... Aug 25, 2023 - A CSRF/SSRF vulnerability in jenkinsci/blueocean-plugin allows the leak of sensitive credentials (including GitHub credentials) to an attacker-controlled... cross site request forgery https://groups.google.com/g/kubernetes-security-announce/c/EORqZg0k1l4/m/TtD-q0v7AgAJ [Security Advisory] CVE-2025-13281: Portworx Half-Blind SSRF in kube-controller-manager https://advisories.gitlab.com/maven/org.apache.kylin/kylin-server/CVE-2025-61735/ Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability | GitLab Advisory Database (GLAD) CVE-2025-61735 Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability: Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue... server side request forgeryapache kylin https://advisories.gitlab.com/pypi/fastmcp/CVE-2026-32871/ FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability | GitLab Advisory Database... https://serversecurityauthority.com/server-side-request-forgery-prevention/ Server-Side Request Forgery (SSRF) Prevention Server-Side Request Forgery SSRF represents one of the most operationally dangerous classes of web application vulnerability, enabling attackers to weaponize a... server side request forgeryssrfprevention https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-33039/ AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy | GitLab... CVE-2026-33039 AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy: The plugin/LiveLinks/proxy.php endpoint validates... https://advisories.gitlab.com/cargo/activitypub_federation/CVE-2025-25194/ Server-Side Request Forgery (SSRF) in activitypub_federation | GitLab Advisory Database (GLAD) CVE-2025-25194 Server-Side Request Forgery (SSRF) in activitypub_federation: This vulnerability allows a user to bypass any predefined hardcoded URL path or... server side request forgery https://techdocs.f5.com/en-us/bigip-21-1-0/big-ip-asm-implementations/mitigating-ssrf/configuring-ssrf-host-list.html Configuring SSRF hosts list | BIG-IP Documentation Apr 22, 2026 - Usage information and technical documentation for BIG-IP and other related F5 products big ipconfiguringssrfhostslist https://advisories.gitlab.com/pypi/plane/CVE-2026-30242/ Plane has SSRF via Incomplete IP Validation in Webhook URL Serializer | GitLab Advisory Database... CVE-2026-30242 Plane has SSRF via Incomplete IP Validation in Webhook URL Serializer: The webhook URL validation in plane/app/serializers/webhook.py only... https://advisories.gitlab.com/pypi/vllm/CVE-2026-34753/ vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url ` | GitLab Advisory Database... CVE-2026-34753 vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `: A Server Side Request Forgery (SSRF) vulnerability in... server side request forgery https://advisories.gitlab.com/golang/github.com/greenpau/caddy-security/CVE-2024-21498/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2024-21498 Server-Side Request Forgery (SSRF): All versions of the package github.com/greenpau/caddy-security is vulnerable to Server-side Request Forgery... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/composer/shopxo/shopxo/CVE-2025-28094/ ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) | GitLab... CVE-2025-28094 ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS): shopxo v6.4.0 has a ssrf/xss vulnerability in multiple... server side request forgery https://advisories.gitlab.com/golang/github.com/zitadel/zitadel/v2/CVE-2026-27945/ ZITADEL has potential SSRF via Actions | GitLab Advisory Database (GLAD) CVE-2026-27945 ZITADEL has potential SSRF via Actions: ZITADEL Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook... zitadelpotentialssrfviaactions https://advisories.gitlab.com/npm/openclaw/GHSA-vr5g-mmx7-h897/ OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation | GitLab Advisory... GHSA-vr5g-mmx7-h897 OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation: Browser SSRF Policy Bypass via Interaction-Triggered... https://advisories.gitlab.com/golang/github.com/matrix-org/gomatrixserverlib/CVE-2024-52594/ Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation | GitLab Advisory... CVE-2024-52594 Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation: Gomatrixserverlib is vulnerable to server-side request... server side request forgery https://advisories.gitlab.com/npm/@frontmcp/sdk/CVE-2026-39885/ mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications |... CVE-2026-39885 mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications: The mcp-from-openapi library uses... https://cheat-sheets.portswigger.net/ URL validation bypass cheat sheet for SSRF/CORS/Redirect - 2024 Edition cheat sheeturlvalidationbypass https://advisories.gitlab.com/gem/httparty/CVE-2025-68696/ httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage | GitLab Advisory Database... CVE-2025-68696 httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage: There may be an SSRF vulnerability in httparty. This issue can pose a... https://advisories.gitlab.com/pypi/changedetection.io/CVE-2026-27696/ changedetection.io is Vulnerable to SSRF via Watch URLs | GitLab Advisory Database (GLAD) CVE-2026-27696 changedetection.io is Vulnerable to SSRF via Watch URLs: Changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL... https://advisories.gitlab.com/composer/yuan1994/tpadmin/CVE-2023-1971/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2023-1971 Server-Side Request Forgery (SSRF): ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in yuan1994... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/composer/admidio/admidio/CVE-2026-32812/ Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint... CVE-2026-32812 Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint: The SSO metadata fetch endpoint at... https://advisories.gitlab.com/golang/code.vikunja.io/api/CVE-2026-33675/ Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal... CVE-2026-33675 Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources: The migration helper... https://advisories.gitlab.com/pypi/lmdeploy/CVE-2026-33626/ LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading | GitLab Advisory... CVE-2026-33626 LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading: A Server-Side Request Forgery (SSRF) vulnerability exists in... server side request forgery https://advisories.gitlab.com/composer/automad/automad/CVE-2023-7037/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2023-7037 Server-Side Request Forgery (SSRF): A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/npm/@langchain/community/GHSA-gf3v-fwqg-4vh7/ @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin... GHSA-gf3v-fwqg-4vh7 @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation: The RecursiveUrlLoader class in... https://advisories.gitlab.com/golang/github.com/centrifugal/centrifugo/v5/CVE-2026-32301/ Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL | GitLab... CVE-2026-32301 Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL: Centrifugo is vulnerable to Server-Side Request Forgery... https://advisories.gitlab.com/npm/openclaw/CVE-2026-28476/ OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication | GitLab Advisory... CVE-2026-28476 OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication: The optional Tlon (Urbit) extension previously accepted a... https://advisories.gitlab.com/maven/org.apache.cxf/cxf-rt-databinding-aegis/CVE-2024-28752/ SSRF vulnerability using the Aegis DataBinding in Apache CXF | GitLab Advisory Database (GLAD) CVE-2024-28752 SSRF vulnerability using the Aegis DataBinding in Apache CXF: A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before... https://advisories.gitlab.com/npm/openclaw/CVE-2026-28467/ OpenClaw affected by SSRF via attachment/media URL hydration | GitLab Advisory Database (GLAD) CVE-2026-28467 OpenClaw affected by SSRF via attachment/media URL hydration: Versions of the openclaw npm package prior to 2026.2.2 could be coerced into... https://github.com/ksharinarayanan/SSRFire GitHub - ksharinarayanan/SSRFire: An automated SSRF finder. Just give the domain name and your... An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects - ksharinarayanan/SSRFire https://advisories.gitlab.com/maven/com.liferay/com.liferay.object.service/CVE-2025-43763/ Liferay Portal is vulnerable to SSRF through custom object attachment fields | GitLab Advisory... CVE-2025-43763 Liferay Portal is vulnerable to SSRF through custom object attachment fields: A server-side request forgery (SSRF) vulnerability exist in the... https://advisories.gitlab.com/maven/org.apache.xmlgraphics/batik-dom/CVE-2022-41704/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2022-41704 Server-Side Request Forgery (SSRF): A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG.... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/npm/openclaw/GHSA-35cq-wv6v-88xf/ Duplicate Advisory: OpenClaw affected by SSRF via unguarded image download in fal provider | GitLab... GHSA-35cq-wv6v-88xf Duplicate Advisory: OpenClaw affected by SSRF via unguarded image download in fal provider: Duplicate Advisory This advisory has been... https://advisories.gitlab.com/npm/@backstage/plugin-auth-backend/CVE-2026-32236/ @backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch | GitLab Advisory Database... CVE-2026-32236 @backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch: A Server-Side Request Forgery (SSRF) vulnerability exists in... https://advisories.gitlab.com/npm/a11y-mcp/CVE-2026-5323/ a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function | GitLab Advisory... CVE-2026-5323 a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function: A vulnerability was found in priyankark a11y-mcp up to 1.0.5.... server side request forgery https://advisories.gitlab.com/npm/flowise/GHSA-qqvm-66q4-vf5c/ Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure) |... GHSA-qqvm-66q4-vf5c Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure): Flowise introduced SSRF protections... https://advisories.gitlab.com/npm/ghost/CVE-2025-9862/ Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark | GitLab Advisory... CVE-2025-9862 Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark: A vulnerability in Ghost's oEmbed mechanism allows staff users to... server side request forgery https://advisories.gitlab.com/npm/i18next-http-middleware/CVE-2026-42353/ i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace... CVE-2026-42353 i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters: Versions of i18next-http-middleware... https://advisories.gitlab.com/golang/github.com/docker/model-runner/CVE-2026-33990/ Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF) | GitLab... CVE-2026-33990 Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF): Docker Model Runner contains an SSRF vulnerability in... server side request forgerydocker model runner https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-38527/ Webkul Krayin CRM has Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2026-38527 Webkul Krayin CRM has Server-Side Request Forgery (SSRF): A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of... server side request forgery https://advisories.gitlab.com/golang/miniflux.app/v2/CVE-2026-21885/ Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources | GitLab... CVE-2026-21885 Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources: Miniflux's media proxy endpoint (GET... https://advisories.gitlab.com/maven/org.geoserver/gs-wfs/GHSA-68cf-j696-wvv9/ GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx | GitLab... GHSA-68cf-j696-wvv9 GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx: Missing checks allow for SSRF to specific targets using... https://gitlab.eclipse.org/security/cve-assignment/-/issues/103 [CVE Request] CWE-918: Unauthenticated Blind Server-Side Request Forgery (SSRF) in Eclipse BaSyx V2... CVE Reservation Request The Eclipse Foundation is a Common Vulnerabilities and Exposures (CVE) Numbering Authority.... https://advisories.gitlab.com/maven/org.apache.xmlgraphics/batik-rasterizer/CVE-2022-38648/ Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD) CVE-2022-38648 Server-Side Request Forgery (SSRF): Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch... server side request forgeryssrfgitlabadvisorydatabase https://advisories.gitlab.com/npm/openclaw/GHSA-w8g9-x8gx-crmm/ OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets... GHSA-w8g9-x8gx-crmm OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable: Strict browser SSRF bypass in... https://dev.to/aws-builders/aws-security-stories-042-owasp-ssrf-562i AWS Security Stories #04.2: OWASP - SSRF - DEV Community Server-Side Request Forgery (SSRF) is a web application vulnerability that allows an attacker to... Tagged with devops, gratitude, tooling. aws securitystoriesowaspssrfdev