Server-Side Request Forgery Vulnerabilities

9 advisories classified as Server-Side Request Forgery

9

Total CVEs

3

Critical

6

High

CVE-2026-40089

Apr 9, 2026

Critical (9.9)

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API c...

Read Advisory

CVE-2026-33107

Apr 3, 2026

Critical (10.0)

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-34163

Mar 31, 2026

High (7.7)

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept ...

Read Advisory

CVE-2026-34504

Mar 31, 2026

High (8.3)

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or c...

Read Advisory

CVE-2026-5016

Mar 28, 2026

High (7.3)

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-sid...

Read Advisory

CVE-2026-22742

Mar 27, 2026

High (8.6)

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. I...

Read Advisory

CVE-2026-32169

Mar 19, 2026

Critical (10.0)

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-30834

Mar 7, 2026

High (7.5)

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /download endpoint all...

Read Advisory

CVE-2026-0745

Feb 14, 2026

High (7.2)

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' funct...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.