On this page
CWE-918: Server-Side Request Forgery (SSRF)
Weakness Summary
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
- Canonical source: MITRE CWE-918 (opens in a new tab)
- Published Atomicorp CVE observations: 325
- Distinct affected products in those observations: 250
- Active Atomicorp rules associated with this weakness: 79
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2019-16932 | Visualizer <3.3.1 - Blind Server-Side Request Forgery | visualizer | Attack Blocked by Atomicorp | 344362 |
| CVE-2026-33712 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls | typebot.io | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | kestra | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2021-33690 | SAP NetWeaver Development Infrastructure - Server Side Request Forgery | netweaver development infrastructure | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2026-31818 | Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist | budibase | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-43986 | Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay | Tautulli | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-55166 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and cr | lemur | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2013-4864 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | Attack Blocked by Atomicorp | 330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647 |
| CVE-2018-14728 | Responsive filemanager 9.13.1 Server-Side Request Forgery | responsive filemanager | Attack Blocked by Atomicorp | 392301 |
| CVE-2020-24881 | OsTicket < 1.14.3 - Server Side Request Forgery | osticket | Attack Blocked by Atomicorp | 340147 , 340148 |
| CVE-2021-22175 | GitLab CI Lint API - Server-Side Request Forgery | gitlab | Attack Blocked by Atomicorp | 344362 , 344370 |
| CVE-2021-24472 | Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery | kentharadio | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2022-31188 | CVAT 2.0 - Server Side Request Forgery | computer vision annotation tool | Detected by Atomicorp | 345493 |
| CVE-2022-38580 | X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF) | skipper | Attack Blocked by Atomicorp | 337110 , 390727 , 392301 , 392648 , 398022 |
| CVE-2023-48022 | Anyscale Ray - Remote Code Execution | ray | Attack Blocked by Atomicorp | 392301 , 392648 |
| CVE-2024-45507 | Apache OFBiz - Remote Code Execution | ofbiz | Attack Blocked by Atomicorp | 340162 , 340163 , 344370 |
| CVE-2026-15732 | WGDashboard Server-Side Request Forgery Vulnerability | WGDashboard | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-30118 | scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability | - | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2019-8982 | Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgery | wavemarker studio | Attack Blocked by Atomicorp | 344360 , 347009 |
| CVE-2026-12564 | Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credenti | Red Hat Ansible Automation Platform 2 | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-12605 | glassfish Server-Side Request Forgery Vulnerability | glassfish | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-53513 | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration | better-auth/sso | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-42596 | Gotenberg < 8.31.0 - Server-Side Request Forgery | gotenberg | Attack Blocked by Atomicorp | 344362 , 398004 |
| CVE-2026-62668 | Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols | grav | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-86123 | SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints | sqlchat | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirect | mlflow | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-66794 | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route | multicluster engine for Kubernetes 2.1 | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-67426 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | flyto-core | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-42281 | MagicMirror <= 2.35.0 - Server-Side Request Forgery | magicmirror | Detected by Atomicorp | 398001 |
| CVE-2026-65057 | Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck | keep | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65317 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass | Verba | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-65318 | Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader | Verba | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-85614 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | openpanel | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-86119 | Webstudio through 0.296.0 SSRF via /cgi proxy routes | webstudio | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2017-14611 | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery | cockpit | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2018-9302 | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery | cockpit | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2026-17552 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten | Plack::App::Prerender | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-44313 | LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function | linkwarden | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-51152 | Server-Side Request Forgery | - | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-75332 | Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability | - | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2021-40438 | Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery | http server | Attack Blocked by Atomicorp | 345271 , 390723 |
| CVE-2026-54157 | LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery | lobe-chat | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-86259 | OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | OpenMAIC | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-82866 | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | common | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2023-39108 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | Attack Blocked by Atomicorp | 340162 , 340165 , 344360 , 347009 |
| CVE-2023-39109 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | Attack Blocked by Atomicorp | 340162 , 340165 , 344360 , 347009 |
| CVE-2023-39110 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | Attack Blocked by Atomicorp | 340165 , 344360 , 347009 |
| CVE-2026-62857 | Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources | fedify | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34367 | InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | Attack Blocked by Atomicorp | 337109 , 337110 , 340147 , 340162 , 340163 , 340165 , 344360 , 344370 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | pathling | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-55245 | Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL | bifrost | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-81093 | Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeleton | actors-mcp-server | Attack Blocked by Atomicorp | 340162 , 340165 , 347009 , 390722 |
| CVE-2026-82270 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* | gateway | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82638 | jina-ai reader Server-Side Request Forgery via disabled private-address guard | reader | Attack Blocked by Atomicorp | 344360 , 347009 , 390719 , 390722 , 398001 , 398021 |
| CVE-2026-85608 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | Douyin TikTok Download API | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85612 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | openpanel | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85666 | ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url | ogx | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85673 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding | LlamaFactory | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85691 | MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url | megaparse | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2021-22214 | Gitlab CE/EE 10.5 - Server-Side Request Forgery | gitlab | Attack Blocked by Atomicorp | 344362 |
| CVE-2022-41412 | perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgery | perfsonar | Attack Blocked by Atomicorp | 340007 |
| CVE-2026-34160 | Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser | chamilo lms | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34577 | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check | postiz | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-35032 | Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner | jellyfin | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-45298 | Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) | dozzle | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-56677 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | 9router | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-7412 | Eclipse BaSyx SSRF Vulnerability | Eclipse BaSyx | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2026-81213 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | Langflow OSS | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-81889 | elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback | elFinder | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-46372 | SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl | SillyTavern | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-51583 | usememos through v0.30.0 Server-Side Request Forgery Vulnerability | - | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-57894 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil | Gitea Open Source Git Server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | Wallos | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-67424 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | flyto-core | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-67428 | Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF | flyto-core | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-68558 | Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) | wekan | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-57862 | Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation | Kanboard | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-62234 | Grav < 2.0.4 SSRF via Unrestricted cURL Protocols | grav | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-72855 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST | server | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-73629 | Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses | Serendipity | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-75898 | RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component | ragflow | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2012-10018 | WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload | mapplic | Attack Blocked by Atomicorp | 346755 , 377360 |
| CVE-2026-22681 | OpenViking < 0.3.4 SSRF via /api/v1/resources | OpenViking | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34576 | Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata | postiz | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34966 | Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass | Gitea | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-52769 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId | yeswiki | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-63313 | 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch | 9router | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65056 | mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering | mcp-webresearch | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-76225 | ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV | arcadedb | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 390109 , 398021 , 398022 |
| CVE-2026-79659 | Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo | Ech0 | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-82243 | Budibase Server before 3.41.3 SSRF with Credential Leakage | server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-84196 | Kyverno before 1.18.0 Server-Side Request Forgery via apiCall | kyverno | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-86771 | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num | snipe-it | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2020-13379 | Grafana 3.0.1-7.0.1 - Server-Side Request Forgery | grafana | Attack Blocked by Atomicorp | 340165 |
| CVE-2024-21893 | Ivanti SAML - Server Side Request Forgery (SSRF) | connect secure | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-16268 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler | Newsletters | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-43910 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | java-client | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-54691 | datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects | datamodel-code-generator | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-61638 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | Wallos | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-77348 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.ph | Wallos | Attack Blocked by Atomicorp | 337109 , 337110 , 340790 , 340791 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82262 | Logto Server-Side Request Forgery via webhook test endpoint | logto | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-34365 | InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34366 | InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-50143 | Actor MCP path authority injection leaks Apify token | apify-mcp-server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-40280 | Gotenberg <= 8.30.1 - Server Side Request Forgery | gotenberg | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 344362 , 398021 , 398022 |
| CVE-2026-34163 | Server-Side Request Forgery via MCP Tools Endpoint in FastGPT | fastgpt | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-34936 | PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback | praisonai | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-39361 | OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_url | openobserve | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-39965 | TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks | typebot.io | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-42345 | FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, a | FastGPT | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-44285 | FastGPT: SSRF Protection Bypass via externalFile in Dataset Preview API | FastGPT | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45806 | Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url | penpot | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-53549 | Termix: Server-Side Request Forgery via Proxy Connectivity Test | Termix | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-58314 | Two SSRF findings in Gitea 1.26.2 | Gitea Open Source Git Server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-61835 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import | directus | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63464 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private | nebula-mesh | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-63764 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass | lmdeploy | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-67346 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | swarms | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus | ip-address | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-71303 | Lemur: Incomplete fix for CVE-2026-55166 – ACME authority update endpoint allows non-admin to replace acme_url with i | lemur | Attack Blocked by Atomicorp | 337109 , 337110 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-71365 | Awx: webhook status callback ssrf leaks the git pat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-77775 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation | Headroom | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022 |
| CVE-2026-45082 | Karakeep has a SSRF Protection Bypass via Redirect Handling | karakeep | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | mcphub | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2019-9621 | Zimbra Collaboration Suite - SSRF | collaboration server | Attack Blocked by Atomicorp | 344372 |
| CVE-2021-40822 | Geoserver - Server-Side Request Forgery | geoserver | Attack Blocked by Atomicorp | 340007 |
| CVE-2021-46107 | Ligeo Archives Ligeo Basics - Server Side Request Forgery | ligeo basics | Attack Blocked by Atomicorp | 340162 , 340165 , 344360 , 347009 |
| CVE-2024-6587 | LiteLLM - Server-Side Request Forgery | litellm | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2025-27817 | Apache Kafka Client - Arbitrary File Read | kafka | Attack Blocked by Atomicorp | 344360 |
| CVE-2025-61884 | Oracle E-Business Suite - Server-Side Request Forgery | configurator | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 341256 , 342259 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-0560 | LolLMS < 2.2.0 - Server-Side Request Forgery | lollms | Attack Blocked by Atomicorp | 360151 |
| CVE-2026-50151 | oras-go: credential forwarding via unvalidated Location header in blob upload | oras | Attack Blocked by Atomicorp | 390719 |
| CVE-2026-59765 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | Gitea Open Source Git Server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-81265 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | Langflow OSS | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2017-9355 | Subsonic 6.1.1 - XML External Entity Injection | subsonic | Attack Blocked by Atomicorp | 390726 , 392301 , 392647 , 392648 |
| CVE-2026-49857 | auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback | auth-fetch-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398004 , 398021 , 398022 |
| CVE-2026-70666 | Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs | lemur | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-33715 | Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action | chamilo lms | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45019 | Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access | chainlit | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-6229 | Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter | Royal Addons for Elementor – Addons and Templates Kit for Elementor | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-22664 | prompts.chat SSRF via Fal.ai Media Status Polling | prompts.chat | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-39370 | WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltr | avideo | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-42339 | New API: SSRF Filter Bypass via 0.0.0.0 | new api | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks | arc | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 , 390719 |
| CVE-2026-54166 | Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass | shelf.nu | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-55537 | PraisonAI: Webhook SSRF via DNS fail-open in JobSubmitRequest.validate_webhook_url() — bypass of CVE-2026-40114 | PraisonAI | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-74247 | Quay: ssrf via build archive_url in quay build api | openshift update service | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-75844 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | arcadedb | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | mcphub | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-79788 | Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Address | dradis-ce | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-80350 | OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL | OneUptime | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-82241 | Budibase backend-core SSRF via incomplete default blacklist | server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82246 | Budibase Server before 3.41.3 SSRF via Query Import | server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-85163 | AVideo Server-Side Request Forgery via epg_link parameter | AVideo | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85164 | WWBN AVideo Server-Side Request Forgery via set_api_userImages | AVideo | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-87821 | Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch | laradashboard | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-87999 | Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch | open-webui | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2019-6793 | GitLab Enterprise Edition - Server-Side Request Forgery | gitlab | Attack Blocked by Atomicorp | 390616 |
| CVE-2026-10107 | MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint | MoviePilot | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34964 | Adminer before 5.5.0 SSRF via PDO DSN Injection | adminer | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-39383 | Gotenberg unauthenticated blind SSRF via unfiltered webhook URL | gotenberg | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-44652 | SillyTavern: SSRF vulnerability in the CORS proxy middleware | SillyTavern | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching | boruta | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-73058 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass | stoatchat | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-81678 | AVideo SSRF Guard Bypass via IPv6 Transition Addresses | AVideo | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-84199 | Kyverno before 1.16.2 SSRF via APICall Feature | kyverno | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-85609 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint | openpanel | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85662 | Marqo 2.26.0 Server-Side Request Forgery via Media URLs | marqo | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-86539 | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint | knowns | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-86806 | opengeos GeoLibre _is_within_roots server-side request forgery | GeoLibre | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 350591 , 390722 , 398021 , 398022 |
| CVE-2026-8712 | Wyoming < 1.10.2 SSRF via uri Query Parameter | wyoming | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-89242 | WWBN AVideo Unauthenticated SSRF via login.json.php | AVideo | Attack Blocked by Atomicorp | 337109 , 337110 , 398022 |
| CVE-2026-55421 | Open edX Platform: SSRF in Studio Video Download Endpoint | openedx-platform | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2017-3546 | Oracle PeopleSoft - Server-Side Request Forgery | peoplesoft enterprise peopletools | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2022-1398 | External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery | external media without import | Detected by Atomicorp | 377360 |
| CVE-2023-3188 | Owncast - Server Side Request Forgery | owncast | Attack Blocked by Atomicorp | 392301 |
| CVE-2024-27564 | ChatGPT个人专用版 - Server Side Request Forgery | chatgpt web | Attack Blocked by Atomicorp | 340165 , 344360 , 347009 |
| CVE-2025-54249 | Adobe Experience Manager ≤ 6.5.23.0 – SSRF | experience manager | Attack Blocked by Atomicorp | 390726 , 392647 |
| CVE-2026-15974 | sglang Server-Side Request Forgery Vulnerability | sglang | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-26379 | koha Server-Side Request Forgery Vulnerability | koha | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34740 | AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation | avideo | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-39368 | WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services | avideo | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-46556 | FlaskBB: SSRF in get_image_info() via unrestricted avatar URL | flaskbb | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-52371 | xxl-job v3.4.0 Server-Side Request Forgery Vulnerability | xxl-job v3.4.0 | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-54054 | Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects | transmute | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-58442 | Repository migration SSRF via multi-answer DNS allow-list bypass | Gitea Open Source Git Server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45573 | Decidim: Push subscriptions can be abused for server-side requests | decidim | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-79717 | Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction | Red Hat Ansible Automation Platform 2 | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-82081 | wallabag Server-Side Request Forgery Vulnerability | wallabag | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-42335 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy | MaxKB | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-44284 | FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution | FastGPT | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-49120 | Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint | medplum | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-54020 | Open WebUI: DNS Rebinding SSRF Bypass | open-webui | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63107 | LimeSurvey SSRF via REST API Survey Template Host Header | LimeSurvey | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63643 | MagicMirror: ssrf calendar .js | MagicMirror | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-63731 | HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint | hyperdx | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-63769 | Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method | huginn | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65593 | n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters | n8n | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-67620 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | flowise | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-70667 | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fi | lemur | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-72860 | 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unre | 9router | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-73530 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() | flyto-core | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-86590 | Eclipse Che Server-Side Request Forgery Vulnerability | Eclipse Che | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2017-9506 | Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery | oauth | Attack Blocked by Atomicorp | 382291 |
| CVE-2026-70620 | Odysseus SSRF via Embedding Endpoint Configuration | odysseus | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-86735 | snipe-it before 8.7.0 SSRF via IPv6 transition address bypass | snipe-it | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2020-5775 | Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery | canvas learning management service | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2024-6095 | LocalAI - Partial Local File Read | localai | Attack Blocked by Atomicorp | 344360 |
| CVE-2026-10526 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF | EmbedPress | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34360 | HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing | hl7 fhir core | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45709 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filte | mailpit | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-48053 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | kolibri | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-73243 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass | kkFileView | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2025-13814 | moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgery | mogublog | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-10280 | horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery | mcpilot | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10287 | SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery | SEO Meta Tag Extractor | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16125 | zevorn rt-claw http_request net.c claw_net_post server-side request forgery | rt-claw | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16127 | zevorn rt-claw http_request tool_net.c claw_net_post server-side request forgery | rt-claw | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16128 | zevorn rt-claw http_request swarm.c receiver_thread server-side request forgery | rt-claw | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-16910 | Quay: ssrf in red hat quay notification webhooks (slack/generic) | Red Hat OpenShift Update Service | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-18973 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery | super-agent-party | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19000 | JeecgBoot Anonymous Chat Attachment send server-side request forgery | JeecgBoot | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19374 | adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery | api-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19753 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery | mcp-rdf-explorer | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-5346 | huimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgery | hm editor | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5832 | atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery | api-lab-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-7178 | ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery | nextchat | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-7221 | TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery | CloudBase-MCP | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-7223 | BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery | HyperChat | Attack Blocked by Atomicorp | 334168 , 390719 |
| CVE-2026-76795 | AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery | PullMD | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-81421 | ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery | sentry-selfhosted-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-82630 | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery | PowerJob | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82801 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery | earthdata-search | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82802 | NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery | earthdata-search | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | cms | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-86237 | openagents-org openagents http.py test_default_model server-side request forgery | openagents | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-86273 | projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgery | siga | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-9372 | ItzCrazyKns Vane Model Provider API route.ts server-side request forgery | Vane | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-34590 | Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation | postiz | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-48483 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server | typebot.io | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-48762 | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler | typebot.io | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-7798 | FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 340464 , 340465 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2024-20404 | Cisco Finesse - Server-Side Request Forgery (SSRF) | finesse | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-14860 | Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery | Podcast Player | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16536 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id | Simple Google Calendar Outlook Events Widget | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19956 | gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgery | facebook-ads-mcp-server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-22662 | prompts.chat Blind SSRF via media-generate | prompts.chat | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-44583 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module | Paymenter | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022 |
| CVE-2026-49138 | Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following | nanobot | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-54508 | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution | TREK | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-5538 | QingdaoU OnlineJudge judge_server_heartbeat Endpoint JudgeServer.service_url server-side request forgery | OnlineJudge | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-59231 | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs | Pentestify | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63730 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint | hyperdx | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-64626 | AVideo Encoder downloadURL SSRF via unpinned retry fallback | AVideo | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-64870 | MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation | MaxKB | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-72846 | Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request Forgery | lightdash | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-73082 | Activepieces: Server-side request forgery in MCP tool validation endpoint | activepieces | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-73845 | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer) | ckan-mcp-server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-74858 | jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery | fetcher-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-76239 | Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address | stigmem-node | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-77067 | Omnivore Stored Server-Side Request Forgery via the setWebhook Mutation | omnivore | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-84175 | Eclipse Ditto Uncontrolled Recursion Vulnerability | Eclipse Ditto | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-84207 | Heym before 0.0.98 SSRF via WebSocket endpoints | heym | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85650 | Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel | trigger.dev | Attack Blocked by Atomicorp | 334168 , 337109 , 337110 , 344360 , 390719 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-88892 | OpenPanel SSRF via Unguarded Importer File URL Fetch | openpanel | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-17597 | Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification | Nexus Repository 3 | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-42336 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | MaxKB | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-79671 | Ech0 before 4.4.3 SSRF via DNS Resolution Bypass | Ech0 | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-79723 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | Langflow OSS | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-33534 | EspoCRM <= 9.3.3 - Server-Side Request Forgery | espocrm | Attack Blocked by Atomicorp | 398003 |
| CVE-2026-42188 | Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL | geyser | Attack Blocked by Atomicorp | 337109 , 337110 , 398021 , 398022 |
| CVE-2026-43936 | e107: Server-Side Request Forgery (SSRF) in the remote file fetcher | e107 | Attack Blocked by Atomicorp | 337109 , 337110 , 341737 , 341738 , 344360 , 398021 , 398022 |
| CVE-2026-49856 | @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization | jshookmcp | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-77352 | Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) | Wallos | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-10052 | Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpoints | Red Hat Quay 3 | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-48013 | Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation | shopware | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-48051 | Papra: SSRF via HTTP redirect bypass in webhook delivery | papra | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-77351 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings | Wallos | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-23603 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | Gitea Open Source Git Server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-48707 | InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning | icms2 | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-49262 | Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy | pagible | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-68927 | MobSF: SSRF port restriction bypass in assetlinks_check | Mobile-Security-Framework-MobSF | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-44286 | FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation | FastGPT | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-73087 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher | dozzle | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-77648 | Glance Server-Side Request Forgery Vulnerability | Glance | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2025-13789 | ZenTao model.php makeRequest server-side request forgery | zentao | Attack Blocked by Atomicorp | 337109 , 337110 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2025-13809 | orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgery | orion-ops | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2025-15098 | YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery | yudao-cloud | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10239 | JeecgBoot edit WordUtil.addImage server-side request forgery | JeecgBoot | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-10240 | JeecgBoot test server-side request forgery | the file /airag/airagModel/test | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10241 | jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet | The server processes these URLs | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10274 | indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery | aem-mcp-server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10276 | hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery | Jenkins-server-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10662 | ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery | blender-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10690 | wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery | DesktopCommanderMCP | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-12210 | universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery | python-utcp | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-16074 | AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery | AstrBot | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16124 | nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery | GoClaw | Attack Blocked by Atomicorp | 334168 , 390719 |
| CVE-2026-16194 | zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery | CowAgent | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-16222 | 1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery | CordysCRM | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16223 | 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery | CordysCRM | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-17458 | mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery | openclaw-cn | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-18774 | NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery | hermes-agent | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19040 | MissionSquad mcp-api dcrClients.ts server-side request forgery | mcp-api | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19246 | HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery | nanobot | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19340 | anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery | ProjectHub-Mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19375 | dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery | article-scraper-mcp | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19752 | EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery | mcp-dominican-layer | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19927 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery | OpenBoxes | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19984 | jkawamoto mcp-florence2 init.py get_images server-side request forgery | mcp-florence2 | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-5470 | mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request for | Google-Research-MCP | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5607 | imprvhub mcp-browser-agent URL Parameter handlers.ts CallToolRequestSchema server-side request forgery | mcp-browser-agent | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5803 | bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery | openai-realtime-ui | Attack Blocked by Atomicorp | 337109 , 340162 , 347009 , 390722 |
| CVE-2026-74842 | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery | PromptShopMCP | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-7890 | Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block | concrete cms | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-82905 | sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery | chats | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-83744 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery | Invoice Ninja | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-10583 | nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery | GoClaw | Attack Blocked by Atomicorp | 334168 , 390719 |
| CVE-2026-18856 | Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery | Rhymix CMS | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-82667 | yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forger | GEOFlow | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86240 | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery | FeehiCMS | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-9464 | YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery | yudao-cloud | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19369 | KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery | jira-mcp-server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19373 | PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery | KoboldCPP-MCP-Server | Attack Blocked by Atomicorp | 337109 , 337110 , 344360 , 398021 , 398022 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 330791 | Active | disruptive (deny) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 334168 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340121 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 340464 | Active | disruptive (deny) |
| 340465 | Active | disruptive (deny) |
| 340790 | Active | disruptive (deny) |
| 340791 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 341266 | Active | disruptive (deny) |
| 341737 | Active | disruptive (deny) |
| 341738 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344372 | Active | disruptive (deny) |
| 345271 | Active | non-disruptive (pass) |
| 345493 | Active | non-disruptive (pass) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 350591 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 360151 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 382291 | Active | disruptive (deny) |
| 390109 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390616 | Active | disruptive (deny) |
| 390636 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390719 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390723 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
| 398003 | Active | disruptive (deny) |
| 398004 | Active | disruptive (deny) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims: