On this page

Atomicorp WAF Rule 340165

Rule Summary

Description

This rule detects Remote File Injection attempts. These types of attacks work by tricking an application into download software into itself, which will allow the attacker to download any software they want unto the victims systems, thereby compromising it.

This rules work by detecting the use of a URL as an argument in the URL, for example:

GET /foo.php?foo=

It will also try to determine if this is a local request, and if it is the local request will be allowed.

False Positives

A false positive can occur when an application legitimately sets an argument to a URL, and does this using a previously unknown argument or method to store this URL. The rules contain a large library of known web applications and safe methods for using URLs, and can detect known safe methods and ignore them. However it is possible for a new or custom application to do this in an unknown manner and incorrectly trigger this rule.

It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

If you know that this behavior is acceptable for your application, you can tune it by identifying the argument that is being triggered, and specifically allowing that argument for that application to allow a URL. Please see the Tuning the Atomicorp WAF Rules page for basic information.

Similar Rules

WAF_340163

WAF_340162

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlstypebot.io10.0 (v3.1)Critical
CVE-2026-54745Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABpipelines10.0 (v3.1)Critical
CVE-2026-31818Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklistbudibase9.9 (v3.1)Critical
CVE-2026-43986Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replayTautulli9.9 (v3.1)Critical
CVE-2012-1823PHP CGI v5.3.12/5.4.2 Remote Code Executionphp9.8 (v3.1)Critical
CVE-2024-4577PHP CGI - Argument Injectionphp9.8 (v3.1)Critical
CVE-2026-30118scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability-9.8 (v3.1)Critical
CVE-2026-12564Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credentiRed Hat Ansible Automation Platform 29.6 (v3.1)Critical
CVE-2026-12605glassfish Server-Side Request Forgery Vulnerabilityglassfish9.6 (v3.1)Critical
CVE-2024-27954WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRFAutomatic9.3 (v3.1)Critical
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirectmlflow9.3 (v3.1)Critical
CVE-2026-66794Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public routemulticluster engine for Kubernetes 2.19.3 (v3.1)Critical
CVE-2026-65317Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware BypassVerba9.2 (v4.0)Critical
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkeropenpanel9.2 (v4.0)Critical
CVE-2026-86119Webstudio through 0.296.0 SSRF via /cgi proxy routeswebstudio9.2 (v4.0)Critical
CVE-2026-44313LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Functionlinkwarden9.1 (v3.1)Critical
CVE-2026-75332Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability-9.1 (v3.1)Critical
CVE-2021-25082WordPress Popup Builder < 4.0.7 - Remote Code Executionpopup builder8.8 (v3.1)High
CVE-2023-39108rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2023-39109rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2023-39110rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High
CVE-2026-79662Ech0 before 4.7.3 OAuth Redirect URI Validation BypassEch08.8 (v4.0)High
CVE-2025-34031Moodle Jmol Filter 6.1 - Local File Inclusionjmol8.7 (v4.0)High
CVE-2026-34367InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.7 (v3.1)High
CVE-2026-81093Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeletonactors-mcp-server8.7 (v4.0)High
CVE-2026-82270Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*gateway8.7 (v4.0)High
CVE-2026-85608Douyin_TikTok_Download_API 4.1.2 SSRF via url parameterDouyin TikTok Download API8.7 (v4.0)High
CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpointsopenpanel8.7 (v4.0)High
CVE-2026-85673LLaMA-Factory SSRF Guard Bypass via Redirect and DNS RebindingLlamaFactory8.7 (v4.0)High
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata serchamilo lms8.6 (v3.1)High
CVE-2026-34577Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Checkpostiz8.6 (v3.1)High
CVE-2026-61640Wallos: SSRF via OIDC Token/UserInfo URL ConfigurationWallos8.5 (v4.0)High
CVE-2026-67424Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationflyto-core8.5 (v3.1)High
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret ExfiltrationFlowise8.5 (v4.0)High
CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and RESTserver8.4 (v4.0)High
CVE-2026-52769YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyIdyeswiki8.3 (v3.1)High
CVE-2020-13379Grafana 3.0.1-7.0.1 - Server-Side Request Forgerygrafana8.2 (v3.1)High
CVE-2026-16268Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerNewsletters8.2 (v3.1)High
CVE-2026-43910Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorjava-client8.2 (v3.1)High
CVE-2026-54691datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirectsdatamodel-code-generator8.2 (v3.1)High
CVE-2026-82262Logto Server-Side Request Forgery via webhook test endpointlogto8.2 (v4.0)High
CVE-2024-30188Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Writedolphinscheduler8.1 (v3.1)High
CVE-2026-34365InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High
CVE-2026-34366InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High
CVE-2026-34936PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallbackpraisonai7.7 (v3.1)High
CVE-2026-42345FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, aFastGPT7.7 (v3.1)High
CVE-2026-53549Termix: Server-Side Request Forgery via Proxy Connectivity TestTermix7.7 (v3.1)High
CVE-2026-63764LMDeploy Server-Side Request Forgery via HTTP Redirect Bypasslmdeploy7.7 (v4.0)High
CVE-2026-67346Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypassswarms7.7 (v4.0)High
CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trusip-address7.7 (v4.0)High
CVE-2026-77775Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address ValidationHeadroom7.7 (v4.0)High
CVE-2026-79749MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validationmcphub7.6 (v4.0)High
CVE-2018-19458PHP Proxy 3.0.3 - Local File Inclusionphp-proxy7.5 (v3.0)High
CVE-2018-20463WordPress JSmol2WP <=1.07 - Local File Inclusionjsmol2wp7.5 (v3.0)High
CVE-2021-41277Metabase - Local File Inclusionmetabase7.5 (v3.1)High
CVE-2021-43734kkFileview v4.0.0 - Local File Inclusionkkfileview7.5 (v3.1)High
CVE-2021-46107Ligeo Archives Ligeo Basics - Server Side Request Forgeryligeo basics7.5 (v3.1)High
CVE-2022-47501Apache OFBiz < 18.12.07 - Local File Inclusionofbiz7.5 (v3.1)High
CVE-2023-22047Oracle Peoplesoft - Unauthenticated File Readpeoplesoft enterprise7.5 (v3.1)High
CVE-2025-61884Oracle E-Business Suite - Server-Side Request Forgeryconfigurator7.5 (v3.1)High
CVE-2026-3576Planyo Online Reservation System <= 3.0 - Arbitrary File ReadPlanyo online reservation system7.2 (v3.1)High
CVE-2026-22664prompts.chat SSRF via Fal.ai Media Status Pollingprompts.chat7.1 (v4.0)High
CVE-2026-75844ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypassarcadedb7.1 (v4.0)High
CVE-2026-79747MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxymcphub7.1 (v3.1)High
CVE-2026-85164WWBN AVideo Server-Side Request Forgery via set_api_userImagesAVideo7.1 (v4.0)High
CVE-2026-10107MoviePilot v2 SSRF via /api/v1/system/img/{proxy} EndpointMoviePilot7.0 (v4.0)High
CVE-2025-1743Pichome 2.1.0 - Arbitrary File ReadPichome6.9 (v4.0)Medium
CVE-2026-34964Adminer before 5.5.0 SSRF via PDO DSN Injectionadminer6.9 (v4.0)Medium
CVE-2026-44652SillyTavern: SSRF vulnerability in the CORS proxy middlewareSillyTavern6.9 (v4.0)Medium
CVE-2026-54885Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetchingboruta6.9 (v4.0)Medium
CVE-2026-73058stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypassstoatchat6.9 (v4.0)Medium
CVE-2026-81678AVideo SSRF Guard Bypass via IPv6 Transition AddressesAVideo6.9 (v4.0)Medium
CVE-2026-85609Openpanel before 2.3.0 SSRF via Site Checker Endpointopenpanel6.9 (v4.0)Medium
CVE-2026-86806opengeos GeoLibre _is_within_roots server-side request forgeryGeoLibre6.9 (v4.0)Medium
CVE-2026-8712Wyoming < 1.10.2 SSRF via uri Query Parameterwyoming6.9 (v4.0)Medium
CVE-2014-2383Dompdf < v0.6.0 - Local File Inclusiondompdf6.8 (v2.0)Medium
CVE-2022-37299Shirne CMS 1.2.0 - Local File Inclusionshirne cms6.5 (v3.1)Medium
CVE-2024-27564ChatGPT个人专用版 - Server Side Request Forgerychatgpt web6.5 (v3.1)Medium
CVE-2024-36527Puppeteer Renderer - Directory Traversal-6.5 (v3.1)Medium
CVE-2026-15974sglang Server-Side Request Forgery Vulnerabilitysglang6.5 (v3.1)Medium
CVE-2012-3153Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153)fusion middleware6.4 (v2.0)Medium
CVE-2026-42335MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing DiscrepancyMaxKB6.3 (v4.0)Medium
CVE-2026-42344FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpointsFastGPT6.3 (v3.1)Medium
CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypassopen-webui6.3 (v3.1)Medium
CVE-2026-63107LimeSurvey SSRF via REST API Survey Template Host HeaderLimeSurvey6.3 (v4.0)Medium
CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-Listflowise6.3 (v4.0)Medium
CVE-2026-73530Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()flyto-core6.3 (v4.0)Medium
CVE-2022-0346WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Executionxml sitemap generator6.1 (v3.1)Medium
CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutfreescout6.1 (v3.1)Medium
CVE-2026-10526EmbedPress < 4.6.1 - Unauthenticated Blind SSRFEmbedPress5.8 (v3.1)Medium
CVE-2026-45709Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filtemailpit5.8 (v3.1)Medium
CVE-2026-48053Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewsetkolibri5.8 (v3.1)Medium
CVE-2026-73243kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypasskkFileView5.8 (v3.1)Medium
CVE-2026-18973heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgerysuper-agent-party5.5 (v4.0)Medium
CVE-2026-19753Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgerymcp-rdf-explorer5.5 (v4.0)Medium
CVE-2026-7178ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgerynextchat5.5 (v4.0)Medium
CVE-2026-7221TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgeryCloudBase-MCP5.5 (v4.0)Medium
CVE-2026-76795AeternaLabsHQ PullMD REST API Endpoint api server-side request forgeryPullMD5.5 (v4.0)Medium
CVE-2026-82801NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgeryearthdata-search5.5 (v4.0)Medium
CVE-2026-85380light0011 cms UEditor controller.php catchimage server-side request forgerycms5.5 (v4.0)Medium
CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot servertypebot.io5.4 (v3.1)Medium
CVE-2026-7798FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' ParameterFluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution5.4 (v3.1)Medium
CVE-2026-16336trinodb trino OAuth2/OIDC ExternalUriInfo.java redirecttrino5.3 (v4.0)Medium
CVE-2026-16536Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_idSimple Google Calendar Outlook Events Widget5.3 (v3.1)Medium
CVE-2026-34959Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefixadminer5.3 (v4.0)Medium
CVE-2026-44583Paymenter: Blind Unauthenticated SSRF on the Paypal gateway modulePaymenter5.3 (v3.1)Medium
CVE-2026-49138Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Followingnanobot5.3 (v4.0)Medium
CVE-2026-54508TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolutionTREK5.3 (v4.0)Medium
CVE-2026-59231Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLsPentestify5.3 (v4.0)Medium
CVE-2026-63730HyperDX < 2.31.0 SSRF via Webhook Test Endpointhyperdx5.3 (v4.0)Medium
CVE-2026-63768cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned Statecal.diy5.3 (v4.0)Medium
CVE-2026-64626AVideo Encoder downloadURL SSRF via unpinned retry fallbackAVideo5.3 (v4.0)Medium
CVE-2026-74858jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgeryfetcher-mcp5.3 (v4.0)Medium
CVE-2026-82274Twenty Open Redirect via OAuth Propagator Callbacktwenty5.3 (v4.0)Medium
CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium
CVE-2026-35475WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']wegia5.1 (v4.0)Medium
CVE-2026-42336MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL FetchMaxKB5.1 (v4.0)Medium
CVE-2026-89148AVideo Open Redirect via playlistSort.php Referer HeaderAVideo5.1 (v4.0)Medium
CVE-2026-55834Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=nonepocket-id4.3 (v3.1)Medium
CVE-2026-49262Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxypagible3.0 (v3.1)Low
CVE-2026-73087Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcherdozzle2.3 (v4.0)Low
CVE-2026-10239JeecgBoot edit WordUtil.addImage server-side request forgeryJeecgBoot2.1 (v4.0)Low
CVE-2026-11477hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirecthsweb-framework2.1 (v4.0)Low
CVE-2026-12210universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgerypython-utcp2.1 (v4.0)Low
CVE-2026-16194zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgeryCowAgent2.1 (v4.0)Low
CVE-2026-17458mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgeryopenclaw-cn2.1 (v4.0)Low
CVE-2026-19927OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgeryOpenBoxes2.1 (v4.0)Low
CVE-2026-74842Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgeryPromptShopMCP2.1 (v4.0)Low
CVE-2026-83744invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgeryInvoice Ninja2.1 (v4.0)Low
CVE-2026-18856Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgeryRhymix CMS2.0 (v4.0)Low
CVE-2026-86240liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgeryFeehiCMS2.0 (v4.0)Low
CVE-2026-11502JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirectJeecgBoot1.3 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2024-30188 , CVE-2026-69192 , CVE-2026-3576 , CVE-2026-34442 , CVE-2026-34959
CWE-22CVE-2024-27954 , CVE-2021-25082 , CVE-2025-34031 , CVE-2018-20463 , CVE-2021-41277 , CVE-2021-43734 , CVE-2022-47501 , CVE-2025-61884 , CVE-2025-1743 , CVE-2022-37299 , CVE-2024-36527
CWE-77CVE-2012-1823
CWE-78CVE-2024-4577
CWE-79CVE-2022-0346
CWE-93CVE-2025-61884
CWE-200CVE-2021-41277 , CVE-2014-2383
CWE-284CVE-2026-54745
CWE-287CVE-2018-19458 , CVE-2025-61884
CWE-306CVE-2026-34160 , CVE-2023-22047
CWE-352CVE-2026-89148
CWE-367CVE-2026-42344 , CVE-2026-54020 , CVE-2026-42336 , CVE-2026-49262
CWE-441CVE-2026-43910
CWE-444CVE-2025-61884
CWE-501CVE-2025-61884
CWE-601CVE-2026-79662 , CVE-2026-34442 , CVE-2026-16336 , CVE-2026-63768 , CVE-2026-82274 , CVE-2026-35396 , CVE-2026-35398 , CVE-2026-35472 , CVE-2026-35473 , CVE-2026-35475 , CVE-2026-55834 , CVE-2026-11477 , CVE-2026-11502
CWE-639CVE-2026-69250
CWE-829CVE-2026-34442
CWE-862CVE-2026-33712
CWE-918CVE-2026-33712 , CVE-2026-54745 , CVE-2026-31818 , CVE-2026-43986 , CVE-2026-30118 , CVE-2026-12564 , CVE-2026-12605 , CVE-2026-64849 , CVE-2026-66794 , CVE-2026-65317 , CVE-2026-85614 , CVE-2026-86119 , CVE-2026-44313 , CVE-2026-75332 , CVE-2023-39108 , CVE-2023-39109 , CVE-2023-39110 , CVE-2026-34367 , CVE-2026-81093 , CVE-2026-82270 , CVE-2026-85608 , CVE-2026-85612 , CVE-2026-85673 , CVE-2026-34160 , CVE-2026-34577 , CVE-2026-61640 , CVE-2026-67424 , CVE-2026-72855 , CVE-2026-52769 , CVE-2020-13379 , CVE-2026-16268 , CVE-2026-43910 , CVE-2026-54691 , CVE-2026-82262 , CVE-2026-34365 , CVE-2026-34366 , CVE-2026-34936 , CVE-2026-42345 , CVE-2026-53549 , CVE-2026-63764 , CVE-2026-67346 , CVE-2026-69192 , CVE-2026-77775 , CVE-2026-79749 , CVE-2021-46107 , CVE-2025-61884 , CVE-2026-22664 , CVE-2026-75844 , CVE-2026-79747 , CVE-2026-85164 , CVE-2026-10107 , CVE-2026-34964 , CVE-2026-44652 , CVE-2026-54885 , CVE-2026-73058 , CVE-2026-81678 , CVE-2026-85609 , CVE-2026-86806 , CVE-2026-8712 , CVE-2024-27564 , CVE-2026-15974 , CVE-2026-42335 , CVE-2026-54020 , CVE-2026-63107 , CVE-2026-67620 , CVE-2026-73530 , CVE-2026-10526 , CVE-2026-45709 , CVE-2026-48053 , CVE-2026-73243 , CVE-2026-18973 , CVE-2026-19753 , CVE-2026-7178 , CVE-2026-7221 , CVE-2026-76795 , CVE-2026-82801 , CVE-2026-85380 , CVE-2026-48483 , CVE-2026-7798 , CVE-2026-16536 , CVE-2026-44583 , CVE-2026-49138 , CVE-2026-54508 , CVE-2026-59231 , CVE-2026-63730 , CVE-2026-64626 , CVE-2026-74858 , CVE-2026-42336 , CVE-2026-49262 , CVE-2026-73087 , CVE-2026-10239 , CVE-2026-12210 , CVE-2026-16194 , CVE-2026-17458 , CVE-2026-19927 , CVE-2026-74842 , CVE-2026-83744 , CVE-2026-18856 , CVE-2026-86240
CWE-1188CVE-2026-31818

Documentation Source

  • Original wiki page: WAF 340165
  • Source revision: 2217
  • Source revision date: 2012-03-05