On this page

Atomicorp WAF Rule 340162

Rule Summary

Description

This rule detects possible Remote File Injection attempts. These types of attacks work by tricking an application into download software into itself, which will allow the attacker to download any software they want unto the victims systems, thereby compromising it.

This rule works by detecting the use of a URL as an argument.

False Positives

A false positive can occur when an application legitimately sets an argument to a URL, and does this using a previously unknown argument or method to store this URL. The rules contain a large library of known web applications and safe methods for using URLs, and can detect known safe methods and ignore them. However it is possible for a new or custom application to do this in an unknown manner and incorrectly trigger this rule.

It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

If you know that this behavior is acceptable for your application, you can tune it by identifying the argument that is being triggered, and specifically allowing that argument for that application to allow a URL. Please see the Tuning the Atomicorp WAF Rules page for basic information.

Similar Rules

WAF_340163

WAF_340165

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlstypebot.io10.0 (v3.1)Critical
CVE-2026-54745Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABpipelines10.0 (v3.1)Critical
CVE-2021-33690SAP NetWeaver Development Infrastructure - Server Side Request Forgerynetweaver development infrastructure9.9 (v3.1)Critical
CVE-2026-43986Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replayTautulli9.9 (v3.1)Critical
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and crlemur9.9 (v3.1)Critical
CVE-2016-15043WP Mobile Detector <= 3.5 - Unrestricted File Uploadwp mobile detector9.8 (v3.1)Critical
CVE-2019-10647ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)zzzphp9.8 (v3.0)Critical
CVE-2020-9480Apache Spark - Authentication Bypassspark9.8 (v3.1)Critical
CVE-2021-24472Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgerykentharadio9.8 (v3.1)Critical
CVE-2021-3129Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Executionignition9.8 (v3.1)Critical
CVE-2024-2667InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Uploadinstawp connect9.8 (v3.1)Critical
CVE-2024-45507Apache OFBiz - Remote Code Executionofbiz9.8 (v3.1)Critical
CVE-2024-9234GutenKit <= 2.1.0 - Arbitrary File Uploadgutenkit9.8 (v3.1)Critical
CVE-2026-15732WGDashboard Server-Side Request Forgery VulnerabilityWGDashboard9.8 (v3.1)Critical
CVE-2026-67926JeecgBoot v.3.9.2 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-12564Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credentiRed Hat Ansible Automation Platform 29.6 (v3.1)Critical
CVE-2026-12605glassfish Server-Side Request Forgery Vulnerabilityglassfish9.6 (v3.1)Critical
CVE-2026-53513Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationbetter-auth/sso9.6 (v3.1)Critical
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocolsgrav9.4 (v4.0)Critical
CVE-2026-86123SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpointssqlchat9.4 (v4.0)Critical
CVE-2026-34361HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Thefthl7 fhir core9.3 (v3.1)Critical
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirectmlflow9.3 (v3.1)Critical
CVE-2026-42796Arelle < 2.39.10 - Remote Code Executionarelle9.2 (v4.0)Critical
CVE-2026-65317Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware BypassVerba9.2 (v4.0)Critical
CVE-2021-28918Netmask NPM Package - Server-Side Request Forgerynetmask9.1 (v3.1)Critical
CVE-2026-17552Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenPlack::App::Prerender9.1 (v3.1)Critical
CVE-2026-44313LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Functionlinkwarden9.1 (v3.1)Critical
CVE-2026-51152Server-Side Request Forgery-9.1 (v3.1)Critical
CVE-2026-86259OpenMAIC before 1.0.1 SSRF via Environment-Gated URL ValidationOpenMAIC9.0 (v4.0)Critical
CVE-2026-82866@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetchcommon8.9 (v4.0)High
CVE-2021-25082WordPress Popup Builder < 4.0.7 - Remote Code Executionpopup builder8.8 (v3.1)High
CVE-2023-39108rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2023-39109rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2026-40466Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypassactivemq8.8 (v3.1)High
CVE-2026-79662Ech0 before 4.7.3 OAuth Redirect URI Validation BypassEch08.8 (v4.0)High
CVE-2026-34367InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.7 (v3.1)High
CVE-2026-81093Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeletonactors-mcp-server8.7 (v4.0)High
CVE-2026-85666ogx 1.3.1 Server-Side Request Forgery via MCP tool server_urlogx8.7 (v4.0)High
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata serchamilo lms8.6 (v3.1)High
CVE-2026-51583usememos through v0.30.0 Server-Side Request Forgery Vulnerability-8.5 (v3.1)High
CVE-2026-67428Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRFflyto-core8.5 (v3.1)High
CVE-2026-68558Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)wekan8.5 (v3.1)High
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret ExfiltrationFlowise8.5 (v4.0)High
CVE-2026-57862Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP NotationKanboard8.4 (v4.0)High
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocolsgrav8.4 (v4.0)High
CVE-2026-73629Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addressesSerendipity8.4 (v4.0)High
CVE-2026-34966Gitea prior to 1.27.0 SSRF via Migration URI Fetch BypassGitea8.3 (v4.0)High
CVE-2026-52769YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyIdyeswiki8.3 (v3.1)High
CVE-2026-76225ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSVarcadedb8.3 (v4.0)High
CVE-2026-86771Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_numsnipe-it8.3 (v4.0)High
CVE-2026-16268Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerNewsletters8.2 (v3.1)High
CVE-2026-43910Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorjava-client8.2 (v3.1)High
CVE-2026-61638Wallos: SSRF via Test Email Notification - unvalidated SMTP host/portWallos8.2 (v4.0)High
CVE-2026-82262Logto Server-Side Request Forgery via webhook test endpointlogto8.2 (v4.0)High
CVE-2024-30188Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Writedolphinscheduler8.1 (v3.1)High
CVE-2026-11111chrome Security VulnerabilityExampleProduct8.1 (v3.1)High
CVE-2026-34365InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High
CVE-2026-34366InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High
CVE-2026-50143Actor MCP path authority injection leaks Apify tokenapify-mcp-server8.1 (v3.1)High
CVE-2026-40280Gotenberg <= 8.30.1 - Server Side Request Forgerygotenberg7.8 (v4.0)High
CVE-2026-34163Server-Side Request Forgery via MCP Tools Endpoint in FastGPTfastgpt7.7 (v3.1)High
CVE-2026-34936PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallbackpraisonai7.7 (v3.1)High
CVE-2026-44285FastGPT: SSRF Protection Bypass via externalFile in Dataset Preview APIFastGPT7.7 (v3.1)High
CVE-2026-63464Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_privatenebula-mesh7.7 (v3.1)High
CVE-2026-67346Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypassswarms7.7 (v4.0)High
CVE-2026-79749MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validationmcphub7.6 (v4.0)High
CVE-2009-4223KR-Web <=1.1b2 - Remote File Inclusionkr-php web content server7.5 (v2.0)High
CVE-2018-19458PHP Proxy 3.0.3 - Local File Inclusionphp-proxy7.5 (v3.0)High
CVE-2021-46107Ligeo Archives Ligeo Basics - Server Side Request Forgeryligeo basics7.5 (v3.1)High
CVE-2024-1483Mlflow < 2.9.2 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-2928MLflow < 2.11.3 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-3848Mlflow < 2.11.0 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-6587LiteLLM - Server-Side Request Forgerylitellm7.5 (v3.1)High
CVE-2025-61884Oracle E-Business Suite - Server-Side Request Forgeryconfigurator7.5 (v3.1)High
CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataGitea Open Source Git Server7.5 (v3.1)High
CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesLangflow OSS7.5 (v3.1)High
CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer actionchamilo lms7.2 (v3.1)High
CVE-2026-45019Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network accesschainlit7.2 (v3.1)High
CVE-2026-22664prompts.chat SSRF via Fal.ai Media Status Pollingprompts.chat7.1 (v4.0)High
CVE-2026-39370WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltravideo7.1 (v3.1)High
CVE-2026-42339New API: SSRF Filter Bypass via 0.0.0.0new api7.1 (v4.0)High
CVE-2026-53728Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakagemedplum7.1 (v3.1)High
CVE-2026-54166Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypassshelf.nu7.1 (v3.1)High
CVE-2026-75844ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypassarcadedb7.1 (v4.0)High
CVE-2026-79747MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxymcphub7.1 (v3.1)High
CVE-2026-79788Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Addressdradis-ce7.1 (v4.0)High
CVE-2026-80350OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URLOneUptime7.1 (v4.0)High
CVE-2026-85163AVideo Server-Side Request Forgery via epg_link parameterAVideo7.1 (v4.0)High
CVE-2026-85164WWBN AVideo Server-Side Request Forgery via set_api_userImagesAVideo7.1 (v4.0)High
CVE-2026-10107MoviePilot v2 SSRF via /api/v1/system/img/{proxy} EndpointMoviePilot7.0 (v4.0)High
CVE-2025-1743Pichome 2.1.0 - Arbitrary File ReadPichome6.9 (v4.0)Medium
CVE-2026-34964Adminer before 5.5.0 SSRF via PDO DSN Injectionadminer6.9 (v4.0)Medium
CVE-2026-86806opengeos GeoLibre _is_within_roots server-side request forgeryGeoLibre6.9 (v4.0)Medium
CVE-2022-37299Shirne CMS 1.2.0 - Local File Inclusionshirne cms6.5 (v3.1)Medium
CVE-2025-55911ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)clipbucket6.5 (v3.1)Medium
CVE-2026-15974sglang Server-Side Request Forgery Vulnerabilitysglang6.5 (v3.1)Medium
CVE-2026-52371xxl-job v3.4.0 Server-Side Request Forgery Vulnerabilityxxl-job v3.4.06.5 (v3.1)Medium
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypassGitea Open Source Git Server6.5 (v3.1)Medium
CVE-2026-45573Decidim: Push subscriptions can be abused for server-side requestsdecidim6.4 (v3.1)Medium
CVE-2026-44284FastGPT: Stored MCP tool URL SSRF in FastGPT workflow executionFastGPT6.3 (v3.1)Medium
CVE-2026-49120Medplum < 5.1.14 SSRF via FHIR Subscription Endpointmedplum6.3 (v4.0)Medium
CVE-2026-63643MagicMirror: ssrf calendar .jsMagicMirror6.3 (v4.0)Medium
CVE-2026-65593n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parametersn8n6.3 (v4.0)Medium
CVE-2026-70667Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete filemur6.3 (v3.1)Medium
CVE-2020-13121Submitty <= 20.04.01 - Open Redirectsubmitty6.1 (v3.1)Medium
CVE-2021-24210WordPress PhastPress <1.111 - Open Redirectphastpress6.1 (v3.1)Medium
CVE-2021-24495Wordpress Marmoset Viewer <1.9.3 - Cross-Site Scriptingmarmoset viewer6.1 (v3.1)Medium
CVE-2021-25074WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirectwebp converter for media6.1 (v3.1)Medium
CVE-2024-0250Analytics Insights for Google Analytics 4 < 6.3 - Open Redirectanalytics insights6.1 (v3.1)Medium
CVE-2025-32970XWiki WYSIWYG API - Open Redirectxwiki6.1 (v3.1)Medium
CVE-2012-4982Forescout CounterACT 6.3.4.1 - Open Redirectcounteract5.8 (v2.0)Medium
CVE-2020-5775Canvas LMS v2020-07-29 - Blind Server-Side Request Forgerycanvas learning management service5.8 (v3.1)Medium
CVE-2026-34360HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probinghl7 fhir core5.8 (v3.1)Medium
CVE-2026-45709Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filtemailpit5.8 (v3.1)Medium
CVE-2026-48053Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewsetkolibri5.8 (v3.1)Medium
CVE-2026-73243kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypasskkFileView5.8 (v3.1)Medium
CVE-2025-13814moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgerymogublog5.5 (v4.0)Medium
CVE-2025-59342esm.sh <= v136 - Arbitrary File Write via Path Traversalesm.sh5.5 (v4.0)Medium
CVE-2026-10280horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgerymcpilot5.5 (v4.0)Medium
CVE-2026-16128zevorn rt-claw http_request swarm.c receiver_thread server-side request forgeryrt-claw5.5 (v4.0)Medium
CVE-2026-19000JeecgBoot Anonymous Chat Attachment send server-side request forgeryJeecgBoot5.5 (v4.0)Medium
CVE-2026-7178ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgerynextchat5.5 (v4.0)Medium
CVE-2026-7221TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgeryCloudBase-MCP5.5 (v4.0)Medium
CVE-2026-81421ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgerysentry-selfhosted-mcp5.5 (v4.0)Medium
CVE-2026-82630PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgeryPowerJob5.5 (v4.0)Medium
CVE-2026-85380light0011 cms UEditor controller.php catchimage server-side request forgerycms5.5 (v4.0)Medium
CVE-2026-86237openagents-org openagents http.py test_default_model server-side request forgeryopenagents5.5 (v4.0)Medium
CVE-2026-86273projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgerysiga5.5 (v4.0)Medium
CVE-2026-9372ItzCrazyKns Vane Model Provider API route.ts server-side request forgeryVane5.5 (v4.0)Medium
CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot servertypebot.io5.4 (v3.1)Medium
CVE-2026-7798FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' ParameterFluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution5.4 (v3.1)Medium
CVE-2026-16536Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_idSimple Google Calendar Outlook Events Widget5.3 (v3.1)Medium
CVE-2026-54508TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolutionTREK5.3 (v4.0)Medium
CVE-2026-59231Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLsPentestify5.3 (v4.0)Medium
CVE-2026-63768cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned Statecal.diy5.3 (v4.0)Medium
CVE-2026-73845CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer)ckan-mcp-server5.3 (v3.1)Medium
CVE-2026-74858jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgeryfetcher-mcp5.3 (v4.0)Medium
CVE-2026-76239Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_addressstigmem-node5.3 (v4.0)Medium
CVE-2026-82274Twenty Open Redirect via OAuth Propagator Callbacktwenty5.3 (v4.0)Medium
CVE-2026-17597Nexus Repository 3 - Server-Side Request Forgery via Email Configuration VerificationNexus Repository 35.1 (v4.0)Medium
CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-76203CSS sanitizer bypass in Pentestify report themes allows forced outbound requestsPentestify5.1 (v4.0)Medium
CVE-2026-89148AVideo Open Redirect via playlistSort.php Referer HeaderAVideo5.1 (v4.0)Medium
CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesLangflow OSS5.0 (v3.1)Medium
CVE-2020-9314Oracle iPlanet Web Server 7.0.x - Image Injectioniplanet web server4.8 (v3.1)Medium
CVE-2026-49856@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorizationjshookmcp4.3 (v3.1)Medium
CVE-2026-55834Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=nonepocket-id4.3 (v3.1)Medium
CVE-2026-77351Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification SettingsWallos3.5 (v3.1)Low
CVE-2026-44286FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address ValidationFastGPT2.3 (v4.0)Low
CVE-2026-77648Glance Server-Side Request Forgery VulnerabilityGlance2.2 (v3.1)Low
CVE-2025-13809orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgeryorion-ops2.1 (v4.0)Low
CVE-2026-10239JeecgBoot edit WordUtil.addImage server-side request forgeryJeecgBoot2.1 (v4.0)Low
CVE-2026-10241jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNetThe server processes these URLs2.1 (v4.0)Low
CVE-2026-10274indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgeryaem-mcp-server2.1 (v4.0)Low
CVE-2026-10276hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgeryJenkins-server-mcp2.1 (v4.0)Low
CVE-2026-10690wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgeryDesktopCommanderMCP2.1 (v4.0)Low
CVE-2026-11477hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirecthsweb-framework2.1 (v4.0)Low
CVE-2026-162231Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgeryCordysCRM2.1 (v4.0)Low
CVE-2026-17458mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgeryopenclaw-cn2.1 (v4.0)Low
CVE-2026-19040MissionSquad mcp-api dcrClients.ts server-side request forgerymcp-api2.1 (v4.0)Low
CVE-2026-19984jkawamoto mcp-florence2 init.py get_images server-side request forgerymcp-florence22.1 (v4.0)Low
CVE-2026-5803bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgeryopenai-realtime-ui2.1 (v4.0)Low
CVE-2026-74842Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgeryPromptShopMCP2.1 (v4.0)Low
CVE-2026-83744invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgeryInvoice Ninja2.1 (v4.0)Low
CVE-2026-18856Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgeryRhymix CMS2.0 (v4.0)Low
CVE-2026-19369KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgeryjira-mcp-server1.9 (v4.0)Low
CVE-2026-11502JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirectJeecgBoot1.3 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2026-53513 , CVE-2026-40466 , CVE-2024-30188 , CVE-2012-4982 , CVE-2026-73845
CWE-22CVE-2021-25082 , CVE-2024-1483 , CVE-2024-2928 , CVE-2024-3848 , CVE-2025-61884 , CVE-2025-1743 , CVE-2022-37299
CWE-24CVE-2025-59342
CWE-29CVE-2024-2928 , CVE-2024-3848
CWE-77CVE-2026-47670 , CVE-2025-55911
CWE-78CVE-2026-47670
CWE-79CVE-2021-24495 , CVE-2020-9314
CWE-93CVE-2025-61884
CWE-94CVE-2024-45507 , CVE-2026-67926 , CVE-2026-40466 , CVE-2009-4223
CWE-125CVE-2026-11111
CWE-180CVE-2026-76203
CWE-200CVE-2026-58442
CWE-284CVE-2026-54745
CWE-285CVE-2026-55166
CWE-287CVE-2018-19458 , CVE-2025-61884
CWE-306CVE-2020-9480 , CVE-2026-42796 , CVE-2026-86259 , CVE-2026-34160 , CVE-2026-33715
CWE-345CVE-2026-53513 , CVE-2026-53728
CWE-352CVE-2026-89148
CWE-367CVE-2026-70667
CWE-434CVE-2016-15043 , CVE-2019-10647 , CVE-2024-2667
CWE-441CVE-2026-53513 , CVE-2026-43910 , CVE-2026-63643
CWE-444CVE-2025-61884
CWE-501CVE-2025-61884
CWE-552CVE-2026-34361
CWE-601CVE-2026-79662 , CVE-2026-53728 , CVE-2020-13121 , CVE-2021-24210 , CVE-2021-25074 , CVE-2024-0250 , CVE-2025-32970 , CVE-2026-63768 , CVE-2026-82274 , CVE-2026-35396 , CVE-2026-35398 , CVE-2026-35472 , CVE-2026-35473 , CVE-2026-55834 , CVE-2026-11477 , CVE-2026-11502
CWE-625CVE-2026-73845
CWE-639CVE-2026-55166 , CVE-2026-69250
CWE-704CVE-2021-28918
CWE-862CVE-2026-33712 , CVE-2024-9234 , CVE-2026-63464
CWE-918CVE-2026-33712 , CVE-2026-54745 , CVE-2021-33690 , CVE-2026-43986 , CVE-2026-55166 , CVE-2021-24472 , CVE-2024-45507 , CVE-2026-15732 , CVE-2026-12564 , CVE-2026-12605 , CVE-2026-53513 , CVE-2026-62668 , CVE-2026-86123 , CVE-2026-64849 , CVE-2026-65317 , CVE-2026-17552 , CVE-2026-44313 , CVE-2026-51152 , CVE-2026-86259 , CVE-2026-82866 , CVE-2023-39108 , CVE-2023-39109 , CVE-2026-34367 , CVE-2026-81093 , CVE-2026-85666 , CVE-2026-34160 , CVE-2026-51583 , CVE-2026-67428 , CVE-2026-68558 , CVE-2026-57862 , CVE-2026-62234 , CVE-2026-73629 , CVE-2026-34966 , CVE-2026-52769 , CVE-2026-76225 , CVE-2026-86771 , CVE-2026-16268 , CVE-2026-43910 , CVE-2026-61638 , CVE-2026-82262 , CVE-2026-34365 , CVE-2026-34366 , CVE-2026-50143 , CVE-2026-40280 , CVE-2026-34163 , CVE-2026-34936 , CVE-2026-44285 , CVE-2026-63464 , CVE-2026-67346 , CVE-2026-79749 , CVE-2021-46107 , CVE-2024-6587 , CVE-2025-61884 , CVE-2026-59765 , CVE-2026-81265 , CVE-2026-33715 , CVE-2026-45019 , CVE-2026-22664 , CVE-2026-39370 , CVE-2026-42339 , CVE-2026-54166 , CVE-2026-75844 , CVE-2026-79747 , CVE-2026-79788 , CVE-2026-80350 , CVE-2026-85163 , CVE-2026-85164 , CVE-2026-10107 , CVE-2026-34964 , CVE-2026-86806 , CVE-2026-15974 , CVE-2026-52371 , CVE-2026-58442 , CVE-2026-45573 , CVE-2026-44284 , CVE-2026-49120 , CVE-2026-63643 , CVE-2026-65593 , CVE-2026-70667 , CVE-2020-5775 , CVE-2026-34360 , CVE-2026-45709 , CVE-2026-48053 , CVE-2026-73243 , CVE-2025-13814 , CVE-2026-10280 , CVE-2026-16128 , CVE-2026-19000 , CVE-2026-7178 , CVE-2026-7221 , CVE-2026-81421 , CVE-2026-82630 , CVE-2026-85380 , CVE-2026-86237 , CVE-2026-86273 , CVE-2026-9372 , CVE-2026-48483 , CVE-2026-7798 , CVE-2026-16536 , CVE-2026-54508 , CVE-2026-59231 , CVE-2026-73845 , CVE-2026-74858 , CVE-2026-76239 , CVE-2026-17597 , CVE-2026-79723 , CVE-2026-49856 , CVE-2026-77351 , CVE-2026-44286 , CVE-2026-77648 , CVE-2025-13809 , CVE-2026-10239 , CVE-2026-10241 , CVE-2026-10274 , CVE-2026-10276 , CVE-2026-10690 , CVE-2026-16223 , CVE-2026-17458 , CVE-2026-19040 , CVE-2026-19984 , CVE-2026-5803 , CVE-2026-74842 , CVE-2026-83744 , CVE-2026-18856 , CVE-2026-19369

Documentation Source

  • Original wiki page: WAF 340162
  • Source revision: 3858
  • Source revision date: 2013-08-16