On this page
Atomicorp WAF Rule 398001
Rule Summary
- Rule ID: 398001
- Status: Active
- Alert message: Atomicorp.com WAF Rules: SSRF attempt - URL parameter references internal address space
- Observed CWEs: CWE-77 (1), CWE-284 (1), CWE-352 (1), CWE-367 (1), CWE-434 (1), CWE-441 (1), CWE-502 (1), CWE-674 (1), CWE-862 (1), CWE-918 (46), CWE-1188 (1)
- Revision: 2
- Rule severity: Error (3)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: pass
- Public tags: no_ar
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “SSRF attempt - URL parameter references internal address space” in the request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and records the match without a disruptive action.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | 10.0 (v3.1) | Critical |
| CVE-2024-5932 | GiveWP - PHP Object Injection | givewp | 9.8 (v3.1) | Critical |
| CVE-2026-42281 | MagicMirror <= 2.35.0 - Server-Side Request Forgery | magicmirror | 9.2 (v4.0) | Critical |
| CVE-2026-85614 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | openpanel | 9.2 (v4.0) | Critical |
| CVE-2026-51152 | Server-Side Request Forgery | - | 9.1 (v3.1) | Critical |
| CVE-2026-32475 | Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler | Elementor Pro | 9.0 (v3.1) | Critical |
| CVE-2026-82866 | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | common | 8.9 (v4.0) | High |
| CVE-2020-7991 | Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password) | framework | 8.8 (v3.1) | High |
| CVE-2026-55245 | Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL | bifrost | 8.7 (v4.0) | High |
| CVE-2026-82270 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* | gateway | 8.7 (v4.0) | High |
| CVE-2026-82638 | jina-ai reader Server-Side Request Forgery via disabled private-address guard | reader | 8.7 (v4.0) | High |
| CVE-2026-85608 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | Douyin TikTok Download API | 8.7 (v4.0) | High |
| CVE-2026-85612 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | openpanel | 8.7 (v4.0) | High |
| CVE-2026-85666 | ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url | ogx | 8.7 (v4.0) | High |
| CVE-2026-85673 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding | LlamaFactory | 8.7 (v4.0) | High |
| CVE-2026-85691 | MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url | megaparse | 8.7 (v4.0) | High |
| CVE-2026-81889 | elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback | elFinder | 8.6 (v3.1) | High |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | Wallos | 8.5 (v4.0) | High |
| CVE-2026-52769 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId | yeswiki | 8.3 (v3.1) | High |
| CVE-2026-82243 | Budibase Server before 3.41.3 SSRF with Credential Leakage | server | 8.3 (v4.0) | High |
| CVE-2026-61638 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | Wallos | 8.2 (v4.0) | High |
| CVE-2026-77348 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.ph | Wallos | 8.2 (v3.1) | High |
| CVE-2026-82262 | Logto Server-Side Request Forgery via webhook test endpoint | logto | 8.2 (v4.0) | High |
| CVE-2026-63464 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private | nebula-mesh | 7.7 (v3.1) | High |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | mcphub | 7.6 (v4.0) | High |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | mcphub | 7.1 (v3.1) | High |
| CVE-2026-82241 | Budibase backend-core SSRF via incomplete default blacklist | server | 7.1 (v4.0) | High |
| CVE-2026-85163 | AVideo Server-Side Request Forgery via epg_link parameter | AVideo | 7.1 (v4.0) | High |
| CVE-2026-85164 | WWBN AVideo Server-Side Request Forgery via set_api_userImages | AVideo | 7.1 (v4.0) | High |
| CVE-2026-84199 | Kyverno before 1.16.2 SSRF via APICall Feature | kyverno | 6.9 (v4.0) | Medium |
| CVE-2026-85609 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint | openpanel | 6.9 (v4.0) | Medium |
| CVE-2026-85662 | Marqo 2.26.0 Server-Side Request Forgery via Media URLs | marqo | 6.9 (v4.0) | Medium |
| CVE-2026-8712 | Wyoming < 1.10.2 SSRF via uri Query Parameter | wyoming | 6.9 (v4.0) | Medium |
| CVE-2026-55421 | Open edX Platform: SSRF in Studio Video Download Endpoint | openedx-platform | 6.8 (v3.1) | Medium |
| CVE-2025-55911 | ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF) | clipbucket | 6.5 (v3.1) | Medium |
| CVE-2022-3590 | WordPress <= 6.2 - Server Side Request Forgery | WordPress | 5.9 (v3.1) | Medium |
| CVE-2025-13814 | moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgery | mogublog | 5.5 (v4.0) | Medium |
| CVE-2026-82630 | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery | PowerJob | 5.5 (v4.0) | Medium |
| CVE-2026-82801 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-82802 | NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | cms | 5.5 (v4.0) | Medium |
| CVE-2026-84175 | Eclipse Ditto Uncontrolled Recursion Vulnerability | Eclipse Ditto | 5.3 (v4.0) | Medium |
| CVE-2026-84207 | Heym before 0.0.98 SSRF via WebSocket endpoints | heym | 5.3 (v4.0) | Medium |
| CVE-2026-85650 | Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel | trigger.dev | 5.3 (v4.0) | Medium |
| CVE-2026-49856 | @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization | jshookmcp | 4.3 (v3.1) | Medium |
| CVE-2026-77352 | Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) | Wallos | 4.3 (v3.1) | Medium |
| CVE-2026-77351 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings | Wallos | 3.5 (v3.1) | Low |
| CVE-2025-13789 | ZenTao model.php makeRequest server-side request forgery | zentao | 2.1 (v4.0) | Low |
| CVE-2025-13809 | orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgery | orion-ops | 2.1 (v4.0) | Low |
| CVE-2026-82905 | sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery | chats | 2.1 (v4.0) | Low |
| CVE-2026-83744 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery | Invoice Ninja | 2.1 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.