CWE-918 2949 件の CVE MITRE の定義 ↗

CWE-918: Server-Side Request Forgery (SSRF)

概要

CWE-918(Server-Side Request Forgery (SSRF))は各種脆弱性データベースや評価で用いられる弱点タイプを説明します。定義・背景・対応する CVE は以下の各セクションを参照してください。

セキュリティへの影響
セキュリティ影響:製品や文脈に依存します。CVE 記録、深刻度、MITRE の説明を参照して優先度を判断してください。

説明

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

適用プラットフォーム

種別 名称 クラス 普遍性 OS / CPE
language Not Language-Specific Undetermined
technology Web Based Undetermined
technology AI/ML Often
technology Web Server Undetermined

このデータベースの関連 CVE

これらの CVE は本データベースでこの弱点に対応付けられており、追跡と検索のために保持されています。

CVE 公開 概要
CVE-2026-16870 2026-07-24 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file downl…
CVE-2026-56167 2026-07-23 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVE-2026-63313 2026-07-23 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured exte…
CVE-2026-48013 2026-07-23 Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbit…
CVE-2026-65516 2026-07-23 Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65496 2026-07-23 Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
CVE-2026-65467 2026-07-23 Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
CVE-2026-65466 2026-07-23 Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
CVE-2026-24639 2026-07-23 Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVE-2026-64873 2026-07-23 Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
CVE-2026-64799 2026-07-23 Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network servic…
CVE-2026-13192 2026-07-22 In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requ…
CVE-2026-65593 2026-07-22 n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute UR…
CVE-2026-65318 2026-07-21 Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET request…
CVE-2026-65317 2026-07-21 Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server i…
CVE-2026-65057 2026-07-21 Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host…
CVE-2026-65056 2026-07-21 mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to t…
CVE-2026-63764 2026-07-21 LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-I…
CVE-2026-47695 2026-07-21 CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, `http.websocket`) blocks requests …
CVE-2026-46556 2026-07-21 FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated u…

コンテンツ投稿

名称
CWE Content Team
組織
MITRE
日付
2013-02-17
バージョン
2.4

コンテンツの変更履歴

日付 名称 バージョン 重要度 コメント
2015-12-07 CWE Content Team 2.9 updated Relationships
2017-01-19 CWE Content Team 2.10 updated Relationships
2017-11-08 CWE Content Team 3.0 updated Applicable_Platforms, References
2018-03-27 CWE Content Team 3.1 updated References
2019-06-20 CWE Content Team 3.3 updated Relationships
2020-02-24 CWE Content Team 4.0 updated Applicable_Platforms, Relationships
2021-07-20 CWE Content Team 4.5 updated References, Related_Attack_Patterns, Relationships
2021-10-28 CWE Content Team 4.6 updated Relationships
2022-06-28 CWE Content Team 4.8 updated Observed_Examples, Relationships
2022-10-13 CWE Content Team 4.9 updated Observed_Examples
2023-04-27 CWE Content Team 4.11 updated Detection_Factors, References, Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes, Relationships
2024-11-19 CWE Content Team 4.16 updated Alternate_Terms, Common_Consequences, Description, Diagram, Observed_Examples, Relationships
2025-09-09 CWE Content Team 4.18 updated Applicable_Platforms, Observed_Examples, References
2025-12-11 CWE Content Team 4.19 updated Applicable_Platforms, Demonstrative_Examples, References, Relationships, Weakness_Ordinalities
2026-04-30 CWE Content Team 4.20 updated Applicable_Platforms, Observed_Examples, References, Relationships

貢献

タイプ 名称 日付 コメント
Content Abhi Balakrishnan 2024-02-29 Provided diagram to improve CWE usability
Content Affan Ahmed 2025-02-08 Provided a PHP-based demonstrative example
cvelogic Threat Intelligence