On this page
Atomicorp WAF Rule 340165
Rule Summary
- Rule ID: 340165
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)
- Observed CWEs: CWE-20 (5), CWE-22 (11), CWE-77 (1), CWE-78 (1), CWE-79 (1), CWE-93 (1), CWE-200 (2), CWE-284 (1), CWE-287 (2), CWE-306 (2), CWE-352 (1), CWE-367 (4), CWE-441 (1), CWE-444 (1), CWE-501 (1), CWE-601 (13), CWE-639 (1), CWE-829 (1), CWE-862 (1), CWE-918 (99), CWE-1188 (1)
- Revision: 292
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request URI
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects Remote File Injection attempts. These types of attacks work by tricking an application into download software into itself, which will allow the attacker to download any software they want unto the victims systems, thereby compromising it.
This rules work by detecting the use of a URL as an argument in the URL, for example:
GET /foo.php?foo=
It will also try to determine if this is a local request, and if it is the local request will be allowed.
False Positives
A false positive can occur when an application legitimately sets an argument to a URL, and does this using a previously unknown argument or method to store this URL. The rules contain a large library of known web applications and safe methods for using URLs, and can detect known safe methods and ignore them. However it is possible for a new or custom application to do this in an unknown manner and incorrectly trigger this rule.
It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
If you know that this behavior is acceptable for your application, you can tune it by identifying the argument that is being triggered, and specifically allowing that argument for that application to allow a URL. Please see the Tuning the Atomicorp WAF Rules page for basic information.
Similar Rules
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2026-33712 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls | typebot.io | 10.0 (v3.1) | Critical |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | 10.0 (v3.1) | Critical |
| CVE-2026-31818 | Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist | budibase | 9.9 (v3.1) | Critical |
| CVE-2026-43986 | Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay | Tautulli | 9.9 (v3.1) | Critical |
| CVE-2012-1823 | PHP CGI v5.3.12/5.4.2 Remote Code Execution | php | 9.8 (v3.1) | Critical |
| CVE-2024-4577 | PHP CGI - Argument Injection | php | 9.8 (v3.1) | Critical |
| CVE-2026-30118 | scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-12564 | Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credenti | Red Hat Ansible Automation Platform 2 | 9.6 (v3.1) | Critical |
| CVE-2026-12605 | glassfish Server-Side Request Forgery Vulnerability | glassfish | 9.6 (v3.1) | Critical |
| CVE-2024-27954 | WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF | Automatic | 9.3 (v3.1) | Critical |
| CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirect | mlflow | 9.3 (v3.1) | Critical |
| CVE-2026-66794 | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route | multicluster engine for Kubernetes 2.1 | 9.3 (v3.1) | Critical |
| CVE-2026-65317 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass | Verba | 9.2 (v4.0) | Critical |
| CVE-2026-85614 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | openpanel | 9.2 (v4.0) | Critical |
| CVE-2026-86119 | Webstudio through 0.296.0 SSRF via /cgi proxy routes | webstudio | 9.2 (v4.0) | Critical |
| CVE-2026-44313 | LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function | linkwarden | 9.1 (v3.1) | Critical |
| CVE-2026-75332 | Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability | - | 9.1 (v3.1) | Critical |
| CVE-2021-25082 | WordPress Popup Builder < 4.0.7 - Remote Code Execution | popup builder | 8.8 (v3.1) | High |
| CVE-2023-39108 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2023-39109 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2023-39110 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 (v3.1) | High |
| CVE-2026-79662 | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass | Ech0 | 8.8 (v4.0) | High |
| CVE-2025-34031 | Moodle Jmol Filter 6.1 - Local File Inclusion | jmol | 8.7 (v4.0) | High |
| CVE-2026-34367 | InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.7 (v3.1) | High |
| CVE-2026-81093 | Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeleton | actors-mcp-server | 8.7 (v4.0) | High |
| CVE-2026-82270 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* | gateway | 8.7 (v4.0) | High |
| CVE-2026-85608 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | Douyin TikTok Download API | 8.7 (v4.0) | High |
| CVE-2026-85612 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | openpanel | 8.7 (v4.0) | High |
| CVE-2026-85673 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding | LlamaFactory | 8.7 (v4.0) | High |
| CVE-2026-34160 | Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser | chamilo lms | 8.6 (v3.1) | High |
| CVE-2026-34577 | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check | postiz | 8.6 (v3.1) | High |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | Wallos | 8.5 (v4.0) | High |
| CVE-2026-67424 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | flyto-core | 8.5 (v3.1) | High |
| CVE-2026-69250 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | Flowise | 8.5 (v4.0) | High |
| CVE-2026-72855 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST | server | 8.4 (v4.0) | High |
| CVE-2026-52769 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId | yeswiki | 8.3 (v3.1) | High |
| CVE-2020-13379 | Grafana 3.0.1-7.0.1 - Server-Side Request Forgery | grafana | 8.2 (v3.1) | High |
| CVE-2026-16268 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler | Newsletters | 8.2 (v3.1) | High |
| CVE-2026-43910 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | java-client | 8.2 (v3.1) | High |
| CVE-2026-54691 | datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects | datamodel-code-generator | 8.2 (v3.1) | High |
| CVE-2026-82262 | Logto Server-Side Request Forgery via webhook test endpoint | logto | 8.2 (v4.0) | High |
| CVE-2024-30188 | Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write | dolphinscheduler | 8.1 (v3.1) | High |
| CVE-2026-34365 | InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.1 (v3.1) | High |
| CVE-2026-34366 | InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field | invoiceshelf | 8.1 (v3.1) | High |
| CVE-2026-34936 | PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback | praisonai | 7.7 (v3.1) | High |
| CVE-2026-42345 | FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, a | FastGPT | 7.7 (v3.1) | High |
| CVE-2026-53549 | Termix: Server-Side Request Forgery via Proxy Connectivity Test | Termix | 7.7 (v3.1) | High |
| CVE-2026-63764 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass | lmdeploy | 7.7 (v4.0) | High |
| CVE-2026-67346 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | swarms | 7.7 (v4.0) | High |
| CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus | ip-address | 7.7 (v4.0) | High |
| CVE-2026-77775 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation | Headroom | 7.7 (v4.0) | High |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | mcphub | 7.6 (v4.0) | High |
| CVE-2018-19458 | PHP Proxy 3.0.3 - Local File Inclusion | php-proxy | 7.5 (v3.0) | High |
| CVE-2018-20463 | WordPress JSmol2WP <=1.07 - Local File Inclusion | jsmol2wp | 7.5 (v3.0) | High |
| CVE-2021-41277 | Metabase - Local File Inclusion | metabase | 7.5 (v3.1) | High |
| CVE-2021-43734 | kkFileview v4.0.0 - Local File Inclusion | kkfileview | 7.5 (v3.1) | High |
| CVE-2021-46107 | Ligeo Archives Ligeo Basics - Server Side Request Forgery | ligeo basics | 7.5 (v3.1) | High |
| CVE-2022-47501 | Apache OFBiz < 18.12.07 - Local File Inclusion | ofbiz | 7.5 (v3.1) | High |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | peoplesoft enterprise | 7.5 (v3.1) | High |
| CVE-2025-61884 | Oracle E-Business Suite - Server-Side Request Forgery | configurator | 7.5 (v3.1) | High |
| CVE-2026-3576 | Planyo Online Reservation System <= 3.0 - Arbitrary File Read | Planyo online reservation system | 7.2 (v3.1) | High |
| CVE-2026-22664 | prompts.chat SSRF via Fal.ai Media Status Polling | prompts.chat | 7.1 (v4.0) | High |
| CVE-2026-75844 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | arcadedb | 7.1 (v4.0) | High |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | mcphub | 7.1 (v3.1) | High |
| CVE-2026-85164 | WWBN AVideo Server-Side Request Forgery via set_api_userImages | AVideo | 7.1 (v4.0) | High |
| CVE-2026-10107 | MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint | MoviePilot | 7.0 (v4.0) | High |
| CVE-2025-1743 | Pichome 2.1.0 - Arbitrary File Read | Pichome | 6.9 (v4.0) | Medium |
| CVE-2026-34964 | Adminer before 5.5.0 SSRF via PDO DSN Injection | adminer | 6.9 (v4.0) | Medium |
| CVE-2026-44652 | SillyTavern: SSRF vulnerability in the CORS proxy middleware | SillyTavern | 6.9 (v4.0) | Medium |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching | boruta | 6.9 (v4.0) | Medium |
| CVE-2026-73058 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass | stoatchat | 6.9 (v4.0) | Medium |
| CVE-2026-81678 | AVideo SSRF Guard Bypass via IPv6 Transition Addresses | AVideo | 6.9 (v4.0) | Medium |
| CVE-2026-85609 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint | openpanel | 6.9 (v4.0) | Medium |
| CVE-2026-86806 | opengeos GeoLibre _is_within_roots server-side request forgery | GeoLibre | 6.9 (v4.0) | Medium |
| CVE-2026-8712 | Wyoming < 1.10.2 SSRF via uri Query Parameter | wyoming | 6.9 (v4.0) | Medium |
| CVE-2014-2383 | Dompdf < v0.6.0 - Local File Inclusion | dompdf | 6.8 (v2.0) | Medium |
| CVE-2022-37299 | Shirne CMS 1.2.0 - Local File Inclusion | shirne cms | 6.5 (v3.1) | Medium |
| CVE-2024-27564 | ChatGPT个人专用版 - Server Side Request Forgery | chatgpt web | 6.5 (v3.1) | Medium |
| CVE-2024-36527 | Puppeteer Renderer - Directory Traversal | - | 6.5 (v3.1) | Medium |
| CVE-2026-15974 | sglang Server-Side Request Forgery Vulnerability | sglang | 6.5 (v3.1) | Medium |
| CVE-2012-3153 | Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153) | fusion middleware | 6.4 (v2.0) | Medium |
| CVE-2026-42335 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy | MaxKB | 6.3 (v4.0) | Medium |
| CVE-2026-42344 | FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-54020 | Open WebUI: DNS Rebinding SSRF Bypass | open-webui | 6.3 (v3.1) | Medium |
| CVE-2026-63107 | LimeSurvey SSRF via REST API Survey Template Host Header | LimeSurvey | 6.3 (v4.0) | Medium |
| CVE-2026-67620 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | flowise | 6.3 (v4.0) | Medium |
| CVE-2026-73530 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() | flyto-core | 6.3 (v4.0) | Medium |
| CVE-2022-0346 | WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Execution | xml sitemap generator | 6.1 (v3.1) | Medium |
| CVE-2026-34442 | FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout | freescout | 6.1 (v3.1) | Medium |
| CVE-2026-10526 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF | EmbedPress | 5.8 (v3.1) | Medium |
| CVE-2026-45709 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filte | mailpit | 5.8 (v3.1) | Medium |
| CVE-2026-48053 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | kolibri | 5.8 (v3.1) | Medium |
| CVE-2026-73243 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass | kkFileView | 5.8 (v3.1) | Medium |
| CVE-2026-18973 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery | super-agent-party | 5.5 (v4.0) | Medium |
| CVE-2026-19753 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery | mcp-rdf-explorer | 5.5 (v4.0) | Medium |
| CVE-2026-7178 | ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery | nextchat | 5.5 (v4.0) | Medium |
| CVE-2026-7221 | TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery | CloudBase-MCP | 5.5 (v4.0) | Medium |
| CVE-2026-76795 | AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery | PullMD | 5.5 (v4.0) | Medium |
| CVE-2026-82801 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | cms | 5.5 (v4.0) | Medium |
| CVE-2026-48483 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server | typebot.io | 5.4 (v3.1) | Medium |
| CVE-2026-7798 | FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | 5.4 (v3.1) | Medium |
| CVE-2026-16336 | trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect | trino | 5.3 (v4.0) | Medium |
| CVE-2026-16536 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id | Simple Google Calendar Outlook Events Widget | 5.3 (v3.1) | Medium |
| CVE-2026-34959 | Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix | adminer | 5.3 (v4.0) | Medium |
| CVE-2026-44583 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module | Paymenter | 5.3 (v3.1) | Medium |
| CVE-2026-49138 | Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following | nanobot | 5.3 (v4.0) | Medium |
| CVE-2026-54508 | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution | TREK | 5.3 (v4.0) | Medium |
| CVE-2026-59231 | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs | Pentestify | 5.3 (v4.0) | Medium |
| CVE-2026-63730 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint | hyperdx | 5.3 (v4.0) | Medium |
| CVE-2026-63768 | cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State | cal.diy | 5.3 (v4.0) | Medium |
| CVE-2026-64626 | AVideo Encoder downloadURL SSRF via unpinned retry fallback | AVideo | 5.3 (v4.0) | Medium |
| CVE-2026-74858 | jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery | fetcher-mcp | 5.3 (v4.0) | Medium |
| CVE-2026-82274 | Twenty Open Redirect via OAuth Propagator Callback | twenty | 5.3 (v4.0) | Medium |
| CVE-2026-35396 | WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35398 | WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35472 | WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35473 | WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35475 | WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-42336 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | MaxKB | 5.1 (v4.0) | Medium |
| CVE-2026-89148 | AVideo Open Redirect via playlistSort.php Referer Header | AVideo | 5.1 (v4.0) | Medium |
| CVE-2026-55834 | Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none | pocket-id | 4.3 (v3.1) | Medium |
| CVE-2026-49262 | Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy | pagible | 3.0 (v3.1) | Low |
| CVE-2026-73087 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher | dozzle | 2.3 (v4.0) | Low |
| CVE-2026-10239 | JeecgBoot edit WordUtil.addImage server-side request forgery | JeecgBoot | 2.1 (v4.0) | Low |
| CVE-2026-11477 | hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect | hsweb-framework | 2.1 (v4.0) | Low |
| CVE-2026-12210 | universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery | python-utcp | 2.1 (v4.0) | Low |
| CVE-2026-16194 | zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery | CowAgent | 2.1 (v4.0) | Low |
| CVE-2026-17458 | mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery | openclaw-cn | 2.1 (v4.0) | Low |
| CVE-2026-19927 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery | OpenBoxes | 2.1 (v4.0) | Low |
| CVE-2026-74842 | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery | PromptShopMCP | 2.1 (v4.0) | Low |
| CVE-2026-83744 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery | Invoice Ninja | 2.1 (v4.0) | Low |
| CVE-2026-18856 | Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery | Rhymix CMS | 2.0 (v4.0) | Low |
| CVE-2026-86240 | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery | FeehiCMS | 2.0 (v4.0) | Low |
| CVE-2026-11502 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect | JeecgBoot | 1.3 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 340165
- Source revision: 2217
- Source revision date: 2012-03-05