https://advisories.gitlab.com/npm/flowise/GHSA-2x8m-83vc-6wv4/
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure) | GitLab Advisory Database (GLAD)
ssrf protectionflowisebypasstoctou
https://advisories.gitlab.com/pypi/mindsdb/CVE-2024-24759/
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding | GitLab Advisory Database (GLAD)
CVE-2024-24759 MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding: DNS rebinding is a method of manipulating resolution of domain names to let...
https://advisories.gitlab.com/npm/flowise/CVE-2026-41270/
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox |...
CVE-2026-41270 Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox: A Server-Side Request Forgery (SSRF)...
https://advisories.gitlab.com/npm/@novu/api/GHSA-4x48-cgf9-q33f/
Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection | GitLab Advisory...
GHSA-4x48-cgf9-q33f Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection: The conditions filter webhook at...
https://advisories.gitlab.com/pypi/weasyprint/CVE-2025-68616/
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect | GitLab...
CVE-2025-68616 WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect: A Server-Side Request Forgery (SSRF) Protection Bypass...
server side request forgery
https://advisories.gitlab.com/npm/openclaw/GHSA-3fv3-6p2v-gxwj/
OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths | GitLab Advisory...
GHSA-3fv3-6p2v-gxwj OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths: QQ Bot Extension: Missing SSRF Protection on All Media Fetch...
https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-43884/
AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL() | GitLab...
CVE-2026-43884 AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL(): Two endpoints in AVideo call isSSRFSafeURL() to...