VulnWatch VulnWatch
← Back to dashboard
#

SSRF

232 entries

Every SSRF entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Medium nvd

CVE-2026-61612: CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerU

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the h...

5.7
CVSS
23 hours ago
High github

Obot: Server-Side Request Forgery via remote MCP server URL

## Summary In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loop...

7.6
CVSS
3 days ago
Low osv

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

## Summary Current vLLM `main` lets an inference request choose the PyNvVideoCodec GPU video decoder through `media_io_kwargs.video.video_backend`, but engine GPU memory reservation is computed only...

3.1
CVSS
5 days ago
Medium osv

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

### Summary A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the `user_co...

SSRF litellm
4.0
CVSS
5 days ago
Critical github

@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft ## Affected - **Repository:** `zereight/gitlab-mcp` - **Affected versions:** All versions through commit `74a8c83` -...

9.6
CVSS
6 days ago
High nvd

CVE-2026-54549: Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, th

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled...

SSRF Agentic / MCP model context protocol
8.3
CVSS
6 days ago
Critical nvd

CVE-2026-12944: IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0)

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib impo...

SSRF langflow
9.6
CVSS
1 week ago
Medium nvd

CVE-2026-12767: IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading...

SSRF langflow
6.5
CVSS
1 week ago
Medium nvd

CVE-2026-12766: IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading t...

SSRF langflow
5.4
CVSS
1 week ago
Medium nvd

CVE-2026-12765: IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading...

SSRF langflow
6.5
CVSS
1 week ago
Medium nvd

CVE-2026-53708: ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for M

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call si...

SSRF a2a
6.6
CVSS
1 week ago
Medium nvd

CVE-2026-90790: A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_not

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of t...

SSRF a2a
5.3
CVSS
1 week ago
High nvd

CVE-2026-19486: A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker...

SSRF gemini
8.7
CVSS
1 week ago
High github

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

### Summary mistral.rs fetches any request-supplied image/audio URL with no host or IP validation, and opens arbitrary local files (a `file://` URL, or any existing relative/absolute path). A remote,...

SSRF mistral openai vllm
7.2
CVSS
1 week ago
Low osv

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

### Summary `vllm/transformers_utils/processors/mimo_v2_omni.py` — the multimodal processor for `MiMoV2OmniForCausalLM` — issues `requests.get(...)` directly on user-supplied image and audio URL stri...

SSRF vllm
3.1
CVSS
1 week ago
Low osv

MLflow AI Gateway permits SSRF through an unvalidated api_base

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value...

SSRF mlflow
3.1
CVSS
1 week ago
Low osv

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

### Summary `vllm/transformers_utils/processors/mimo_v2_omni.py` — the multimodal processor for `MiMoV2OmniForCausalLM` — issues `requests.get(...)` directly on user-supplied image and audio URL stri...

SSRF vllm
3.1
CVSS
1 week ago
Medium nvd

CVE-2026-86122: Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure ar

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cl...

5.3
CVSS
2 weeks ago
Critical github

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

### Maintainer resolution The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f...

SSRF deepseek
8.6
CVSS
2 weeks ago
Medium nvd

CVE-2026-17631: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

SSRF langflow
5.0
CVSS
2 weeks ago
High nvd

CVE-2026-19305: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side r

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

SSRF langflow
8.6
CVSS
2 weeks ago
Medium nvd

CVE-2026-19301: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.

SSRF langflow
5.0
CVSS
2 weeks ago
High nvd

CVE-2026-85686: ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetch

ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticat...

SSRF openai
8.7
CVSS
2 weeks ago
High nvd

CVE-2026-85675: OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content too

OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attac...

Prompt Injection SSRF prompt injection
8.7
CVSS
2 weeks ago
High nvd

CVE-2026-85673: LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL han

LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_...

SSRF openai llama
8.7
CVSS
2 weeks ago