VulnWatch VulnWatch
← Back to dashboard
#

SSRF

163 entries

Every SSRF entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

High nvd

CVE-2026-9081: IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerabil

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The f...

SSRF langflow ollama
7.1
CVSS
2 days ago
Medium nvd

CVE-2026-7657: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and inef

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.

SSRF langflow
6.5
CVSS
2 days ago
High nvd

CVE-2026-71211: MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value...

SSRF mlflow
7.1
CVSS
3 days ago
High github

Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses

## Summary Flowise's HTTP security module (`httpSecurity.ts`) fails to normalize IPv4-mapped IPv6 addresses (e.g., `::ffff:127.0.0.1`, `::ffff:169.254.169.254`) before checking them against the deny...

0.0
CVSS
3 days ago
High nvd

CVE-2026-69250: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unaut...

SSRF large language model
8.5
CVSS
3 days ago
Unknown nvd

CVE-2026-15974: SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.

SSRF sglang
1 week ago
High github

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_post`, `graphql.query`/`graphql.mutation`, `monitor.http_check`, `communication.slack_send`, `notification.{discord,slack...

SSRF anthropic llm
8.5
CVSS
1 week ago
High github

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

## Summary `llm.chat` reads the operator's provider key from the environment (`OPENAI_API_KEY`, `ANTHROPIC_API_KEY`, ...) and sends it in the `Authorization: Bearer` header to `base_url`, a parameter...

SSRF anthropic openai qdrant llm
8.6
CVSS
1 week ago
High github

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

## Summary The capability policy denies the `env.get` and `env.load_dotenv` modules by default, with the stated reason that they read arbitrary host environment variables (API keys, DSNs) and are a s...

SSRF llm
8.6
CVSS
1 week ago
Critical github

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

## Summary `image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); inst...

10.0
CVSS
1 week ago
High nvd

CVE-2026-67428: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, c...

SSRF llm
8.5
CVSS
1 week ago
High nvd

CVE-2026-67425: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them...

SSRF anthropic openai llm
8.6
CVSS
1 week ago
High github

veraPDF Validation XXE via Rich Text

## Summary **Description** An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side R...

SSRF jax
0.0
CVSS
1 week ago
Medium github

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

Hi Novu team, Reporting an SSRF blocklist gap in the shared `validateUrlSsrf` guard. A complete self-contained reproduction is inlined below — copy the four files into a directory and run `docker com...

SSRF replicate
6.8
CVSS
1 week ago
Medium nvd

CVE-2026-17534: Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts...

Prompt Injection SSRF prompt injection
5.5
CVSS
1 week ago
Medium github

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

# Budibase: SSRF via bare fetch() in uploadUrl during AI table generation ## Summary The `uploadUrl()` function in `packages/server/src/utilities/fileUtils.ts` uses a bare `fetch(url)` call without...

SSRF llm
0.0
CVSS
2 weeks ago
High nvd

CVE-2026-65056: mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to t...

Prompt Injection SSRF prompt injection llm
8.3
CVSS
2 weeks ago
Critical nvd

CVE-2026-63764: lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying...

SSRF openai
9.2
CVSS
2 weeks ago
High nvd

CVE-2026-7754: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.

SSRF langflow
7.7
CVSS
3 weeks ago
High github

meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch

## Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch ### Summary The `upload_ad_image` MCP tool in `meta-ads-mcp` v1.0.113 passes an attacker-controlled `ima...

8.3
CVSS
3 weeks ago
Medium nvd

CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat

text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network at...

SSRF openai
6.9
CVSS
3 weeks ago
Low github

ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)

# Security Advisory: SSRF in remote MCP server authentication discovery **Severity:** High. **CWE:** CWE-918. **Affected:** ToolHive through the latest release v0.29.3 and current `main` (HEAD b672d8...

4.7
CVSS
3 weeks ago
Medium nvd

CVE-2026-15746: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool...

SSRF Agentic / MCP large language model ai agent llm
6.9
CVSS
3 weeks ago
High nvd

CVE-2026-15583: A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-...

8.6
CVSS
3 weeks ago
Medium nvd

CVE-2026-24234: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-acces

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of...

6.8
CVSS
3 weeks ago