Search Results (3855 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108850 2026-10-11 5.3 Medium
Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements in report_content to make the server fetch internal or external hosts, leaking image responses in returned PDFs and probing reachability.
CVE-2026-101022 1 Grid Protection Alliance 2 Openhistorian, Openpdc 2026-10-11 4.3 Medium
A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.
CVE-2026-108554 1 Pdfmathtranslate 1 Pdfmathtranslate 2026-10-11 5.3 Medium
PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
CVE-2026-108735 1 Miniflux Project 1 Miniflux 2026-10-11 4.3 Medium
Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services.
CVE-2026-108719 2026-10-11 5 Medium
LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata URLs that deliverWebhook POSTs to without the assertSafeWebhookTarget check, reaching internal services from the worker's network.
CVE-2026-62030 2026-10-11 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
CVE-2026-27350 1 Builderius.io 1 Builderius 2026-10-11 7.2 High
Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery. This issue affects Builderius: from 1.4 through 1.4-beta.
CVE-2026-78024 1 Dell 1 Secure Connect Gateway Policy Manager 2026-10-11 7.7 High
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.
CVE-2026-78027 1 Dell 1 Secure Connect Gateway Policy Manager 2026-10-11 5.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery.
CVE-2026-108572 1 Casdoor 1 Casdoor 2026-10-11 4.3 Medium
A security vulnerability has been detected in Casdoor up to 3.164.0/4.10.0. Affected is the function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation. Such manipulation of the argument pgtUrl leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 4.11.0 is able to address this issue. The name of the patch is 03c6c9aaa2eda5b085ce128ce0d60b34094efbd9/ada08ecd10cbf158f593dee23a8bab63efecf995. It is advisable to upgrade the affected component.
CVE-2026-108542 1 021is 1 Elvix-sdk 2026-10-11 6.3 Medium
A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulation of the argument path results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108523 1 Studio-saelix 1 Sencho 2026-10-11 4.3 Medium
A vulnerability was determined in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repo_url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The presence of this vulnerability remains uncertain at this time. This patch is called 79b86ddcd4aefdd6941f098e35990ab397b13c72. It is advisable to implement a patch to correct this issue. The vendor explains: "Git repository access is an intentional, privileged administrative function. Sencho explicitly supports repositories hosted on private LAN, VPC, VPN, CGNAT, and IPv6 ULA networks. The report does not demonstrate a privilege-boundary bypass or access by an unprivileged user. We therefore dispute the CVE characterization of this behavior. As defense in depth, we have nevertheless hardened repository access. Git HTTPS and SSH connections now validate and pin DNS resolution, reject loopback, link-local, multicast, selected special-use and metadata targets, disable redirects and inherited proxy routing, and retain strict SSH host-key verification."
CVE-2026-108521 1 Studio-saelix 1 Sencho 2026-10-11 4.7 Medium
A vulnerability has been found in Studio-Saelix Sencho up to 0.97.1. Affected by this issue is the function isValidRemoteUrl of the file backend/src/utils/validation.ts of the component Add Remote Node API Endpoint. Such manipulation leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The node API URL could be configured by an authenticated user with node-management permission and used to initiate server-side requests. [T]he report demonstrates server-side request capability but not arbitrary internal response exfiltration."
CVE-2026-108602 1 Helicone 1 Helicone 2026-10-10 4.3 Medium
Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services.
CVE-2026-108594 1 Mealie 1 Mealie 2026-10-10 3.5 Low
Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.
CVE-2026-108583 2026-10-10 4.2 Medium
zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.
CVE-2026-108115 1 Kortix-ai 1 Suna 2026-10-10 4.9 Medium
Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector base_url, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses.
CVE-2026-14521 1 Ibm 4 Datapower Gateway 1050, Datapower Gateway 1060, Datapower Gateway 106cd and 1 more 2026-10-10 4.9 Medium
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2026-76274 1 Splunk 1 Splunk Enterprise 2026-10-10 6.5 Medium
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.
CVE-2026-103958 1 Aws 1 Loom 2026-10-09 7.6 High
Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent. To remediate this issue, users should upgrade to version 1.7.0 or later.