Tag

#SSRF

newsHIGH 8.0

FrontMCP and mcp-from-openapi SSRF Fix Bypass

A bypass vulnerability in FrontMCP and mcp-from-openapi allows an attacker to trigger requests from the server to localhost or private services during tool generation. This affects hosted or multi-user FrontMCP deployments where users can import or configure OpenAPI specs.

1 source
articleHIGH 7.7

Critical Server-Side Request Forgery Vulnerability in Tanium Enforce (CVE-2026-87084)

A server-side request forgery (SSRF) vulnerability, CVE-2026-87084, with a CVSS score of 7.7, was discovered in Tanium's Enforce product. This vulnerability allows attackers to make unauthorized requests on behalf of the server, potentially leading to confidentiality breaches. The vulnerability affects multiple versions of Enforce (2.9, 2.10, and 3.0) and has been addressed by Tanium in recent updates. Organizations are urged to apply patches immediately to mitigate potential risks.

1 source
blogHIGH 7.7

Understanding CVE-2026-47879: Arbitrary Spring Resource Locations in Spring Cloud Gateway

This educational analysis covers CVE-2026-47879, a high-severity vulnerability in Spring Cloud Gateway that allows arbitrary Spring Resource locations for defining the proto descriptor. The vulnerability affects multiple versions of Spring Cloud Gateway and has a CVSS score of 7.7. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection, and defense strategies.

1 source
newsHIGH 8.8

CVE-2026-17123: Royal Elementor Addons Plugin for WordPress Server-Side Request Forgery Vulnerability

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.7.1064. An authenticated attacker with Contributor-level access and above can exploit this vulnerability to make web requests to arbitrary locations, potentially querying and modifying information from internal services. The CVSS score for this vulnerability is 8.8, indicating a high severity level.

1 source
articleCRITICAL 9.5

compliance-trestle URLSecurityValidator SSRF Allowlist Bypass via IPv4-Mapped IPv6 and 0.0.0.0

A critical vulnerability (CVE-2026-52776) was discovered in compliance-trestle, a Python package used for compliance and security. The vulnerability allows for an SSRF (Server-Side Request Forgery) allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0, potentially leading to unauthorized access to cloud-metadata services, loopback administrative interfaces, or RFC 1918 internal networks.

1 source
articleHIGH 8.0

CVE-2026-12971: LearnPress WordPress Plugin SSRF Vulnerability

The LearnPress WordPress plugin before version 4.4.4 is vulnerable to a blind and bounded server-side request forgery (SSRF) attack. This vulnerability allows users with the instructor role to induce the server to issue requests to arbitrary external hosts. The vulnerability has not been actively exploited but poses a significant risk due to its potential for abuse. Organizations using affected versions of the LearnPress plugin should upgrade to version 4.4.4 or later immediately.

1 source
articleMEDIUM 6.3

CVE-2026-19340: Server-Side Request Forgery Vulnerability in ProjectHub-Mcp

A server-side request forgery (SSRF) vulnerability has been identified in ProjectHub-Mcp up to version 5.0.0. The vulnerability, tracked as CVE-2026-19340, has a CVSS score of 6.3 and allows remote attackers to manipulate the URL argument in the Webhooks API, potentially leading to unauthorized access and data breaches. The project vendor, anubissbe, has been informed but has not yet responded. Organizations using affected versions should apply patches or workarounds immediately.

1 source
articleCRITICAL 9.6

Critical CSRF and SSRF Vulnerability in Eclipse GlassFish: CVE-2026-12605

A critical vulnerability, CVE-2026-12605, with a CVSS score of 9.6, was discovered in Eclipse GlassFish versions 8.0.x before 8.0.4. This vulnerability combines Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) flaws in the DownloadServlet ContentSources, allowing an attacker to leak the admin `gfresttoken` and potentially take over the Eclipse GlassFish domain. The vulnerability requires user interaction but can lead to full unauthenticated takeover of the domain. Immediate patching is recommended.

1 source
blogHIGH 8.2

Understanding and Defending Against CVE-2026-16268: Unauthenticated Request Forgery in Newsletters WordPress Plugin

CVE-2026-16268 is a vulnerability in the Newsletters WordPress plugin that allows unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts. This vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. It is not actively exploited in the wild. Understanding this vulnerability is crucial for defenders to protect their WordPress installations.

1 source
articleCRITICAL 10.0

Critical Vulnerability in Prebid Server: CVE-2026-54735

A critical vulnerability (CVE-2026-54735) with a CVSS score of 10 has been discovered in Prebid Server, an open-source solution for real-time advertising auctions. The vulnerability allows crafted bid request parameters to cause server-side requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints. This issue affects Prebid Server versions prior to 4.4.0 and has been fixed in version 4.4.0. Organizations using Prebid Server should immediately upgrade to version 4.4.0 to mitigate this vulnerability.

1 source
newsCRITICAL 10.0

Critical Server-Side Request Forgery Vulnerability in Microsoft Purview Data Governance (CVE-2026-57106)

A critical server-side request forgery (SSRF) vulnerability, CVE-2026-57106, with a CVSS score of 10, has been identified in Microsoft Purview Data Governance. This vulnerability allows an unauthorized attacker to elevate privileges over a network. Immediate action is required to mitigate this critical vulnerability.

1 source
articleHIGH 8.3

Next.js Server-Side Request Forgery Vulnerability in Rewrites via Attacker-Controlled Destination Hostname

A critical vulnerability (CVE-2026-64645) has been discovered in Next.js, a popular React-based framework for building server-rendered, statically generated, and performance-optimized web applications. This vulnerability allows for Server-Side Request Forgery (SSRF) in rewrites via attacker-controlled destination hostnames, with a CVSS score of 8.3. The vulnerability affects Next.js versions >= 12.0.0 and < 15.5.21, as well as versions >= 16.0.0 and < 16.2.11. Immediate patching or workarounds are recommended to prevent potential SSRF attacks.

1 source
articleHIGH 7.5

CVE-2026-16221: fast-uri Vulnerability Allows URL Parsing Discrepancies and Potential SSRF Attacks

A high-severity vulnerability (CVE-2026-16221, CVSS 7.5) exists in fast-uri versions 2.3.1 through 4.1.0, which can lead to URL parsing discrepancies when used with Node's native WHATWG URL parser. This discrepancy can be exploited to bypass host-based security policies, potentially allowing SSRF attacks or steering to unintended destinations, including cloud metadata endpoints or internal hosts. Affected applications should upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3 immediately.

1 source
blogHIGH 8.5

Understanding and Defending Against Server-Side Request Forgery (SSRF) in PraisonAI

This educational analysis covers CVE-2026-61430, a server-side request forgery (SSRF) vulnerability in PraisonAI versions before 1.6.78. The vulnerability allows attackers to bypass SSRF protection using DNS rebinding and retrieve internal HTTP response bodies from private or loopback services. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection strategies, and defensive recommendations.

1 source
articleHIGH 8.6

Critical Confused-Deputy Flaw in Grafana MCP Server Enables Token Exfiltration and SSRF

A high-severity vulnerability (CVE-2026-15583, CVSS 8.6) in Grafana MCP Server allows unauthenticated remote attackers to exfiltrate environment-configured Grafana service-account tokens and conduct SSRF attacks against internal services. The flaw has not been actively exploited but poses a significant risk due to its potential impact. Organizations using Grafana MCP Server version 0.17.1 or earlier are advised to upgrade immediately.

1 source
blogHIGH 7.5

Understanding the oras-go Credential Forwarding Vulnerability via Unvalidated Location Header

The oras-go library is vulnerable to a credential forwarding issue due to an unvalidated Location header during the monolithic blob upload flow. This allows an attacker to leak credentials to an attacker-controlled endpoint and perform client-side SSRF. The vulnerability affects versions prior to 2.6.1 and is tracked under CVE-2026-50151.

1 source
articleHIGH 8.1

Apify Model Context Protocol (MCP) Server: Actor MCP Path Authority Injection Leaks Apify Token

A vulnerability in `@apify/actors-mcp-server` version `0.10.7` allows an attacker to inject a malicious `webServerMcpPath` value, causing the MCP client to exfiltrate the victim's Apify API token to the attacker's server. This is a Server-Side Request Forgery (SSRF) / URL authority injection vulnerability with a CVSS Base Score of 8.1 (High).

1 source
articleHIGH 8.3

CVE-2026-2053: WSO2 API Manager WS-Addressing Header Manipulation Vulnerability

A critical vulnerability (CVE-2026-2053) in WSO2 API Manager's message flow component allows unauthenticated attackers to manipulate WS-Addressing headers, potentially leading to unauthorized access to internal network resources. The vulnerability has a CVSS score of 8.3 and is considered high severity. Affected versions include WSO2 API Manager 3.1.0 to 4.2.0. Immediate patching is recommended.

1 source
articleHIGH 8.7

Lokka Azure Resource Manager URL Path Validation Issue: Critical SSRF Vulnerability

A critical Server-Side Request Forgery (SSRF) vulnerability was discovered in Lokka versions prior to 2.1.2. The issue allows attackers to craft malicious URLs that can alter Azure Resource Manager bearer token transmission, potentially leading to unauthorized access. The vulnerability has a CVSS score of 8.7 and is categorized under CWE-918. Immediate patching to version 2.1.2 or later is strongly recommended.

1 source
blogHIGH 8.0

Understanding and Mitigating Unsafe Remote Filename Resolution in Docling Core

A vulnerability in Docling Core, tracked as CVE-2026-44023, allows for unsafe remote filename resolution, potentially leading to SSRF attacks. This issue affects versions >= 1.5.0 and < 2.74.1 of docling-core. The vulnerability has been patched in version 2.74.1.

1 source