On this page
Atomicorp WAF Rule 398008
Rule Summary
- Rule ID: 398008
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Possible SSRF - non-HTTP scheme in parameter
- Observed CWEs: CWE-20 (3), CWE-22 (3), CWE-29 (2), CWE-73 (1), CWE-74 (1), CWE-94 (2), CWE-284 (1), CWE-306 (1), CWE-502 (10), CWE-611 (1), CWE-862 (2), CWE-918 (23)
- Revision: 1
- Rule severity: Warning (4)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: pass
- Public tags: no_ar
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Possible SSRF - non-HTTP scheme in parameter” in the request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and records the match without a disruptive action.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2026-34976 | Dgraph <=v25.3.0 - Admin Mutation Missing Authorization | dgraph | 10.0 (v3.1) | Critical |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | 10.0 (v3.1) | Critical |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | 9.9 (v3.1) | Critical |
| CVE-2017-18349 | Fastjson Insecure Deserialization - Remote Code Execution | fastjson | 9.8 (v3.0) | Critical |
| CVE-2020-9547 | FasterXML jackson-databind - Deserialization Remote Code Execution | jackson-databind | 9.8 (v3.1) | Critical |
| CVE-2020-9548 | FasterXML Jackson Databind <=2.9.10.4 - Remote Code Execution | jackson-databind | 9.8 (v3.1) | Critical |
| CVE-2023-1177 | Mlflow <2.2.1 - Local File Inclusion | mlflow | 9.8 (v3.1) | Critical |
| CVE-2023-2780 | Mlflow <2.3.1 - Local File Inclusion Bypass | mlflow | 9.8 (v3.1) | Critical |
| CVE-2024-22319 | IBM Operational Decision Manager - JNDI Injection | operational decision manager | 9.8 (v3.1) | Critical |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | 9.8 (v3.1) | Critical |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | 9.2 (v4.0) | Critical |
| CVE-2026-51152 | Server-Side Request Forgery | - | 9.1 (v3.1) | Critical |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | 9.0 (v3.1) | Critical |
| CVE-2026-82866 | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | common | 8.9 (v4.0) | High |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | 8.7 (v4.0) | High |
| CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | nebula-mesh | 8.7 (v4.0) | High |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | 8.7 (v4.0) | High |
| CVE-2026-85666 | ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url | ogx | 8.7 (v4.0) | High |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | tis | 8.3 (v4.0) | High |
| CVE-2026-82243 | Budibase Server before 3.41.3 SSRF with Credential Leakage | server | 8.3 (v4.0) | High |
| CVE-2026-61638 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | Wallos | 8.2 (v4.0) | High |
| CVE-2026-63464 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private | nebula-mesh | 7.7 (v3.1) | High |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | mcphub | 7.6 (v4.0) | High |
| CVE-2026-12720 | Kirki < 6.0.13 - Unauthenticated PHP Object Injection | Kirki | 7.5 (v3.1) | High |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | 7.5 (v3.1) | High |
| CVE-2026-2614 | MLflow <= 3.9.0 - Arbitrary File Read | mlflow | 7.5 (v3.1) | High |
| CVE-2026-61686 | SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop | SolidInvoice | 7.5 (v3.1) | High |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | mcphub | 7.1 (v3.1) | High |
| CVE-2026-82241 | Budibase backend-core SSRF via incomplete default blacklist | server | 7.1 (v4.0) | High |
| CVE-2026-85163 | AVideo Server-Side Request Forgery via epg_link parameter | AVideo | 7.1 (v4.0) | High |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | 6.9 (v4.0) | Medium |
| CVE-2026-85662 | Marqo 2.26.0 Server-Side Request Forgery via Media URLs | marqo | 6.9 (v4.0) | Medium |
| CVE-2025-13814 | moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgery | mogublog | 5.5 (v4.0) | Medium |
| CVE-2026-82630 | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery | PowerJob | 5.5 (v4.0) | Medium |
| CVE-2026-82802 | NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery | earthdata-search | 5.5 (v4.0) | Medium |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | cms | 5.5 (v4.0) | Medium |
| CVE-2026-84207 | Heym before 0.0.98 SSRF via WebSocket endpoints | heym | 5.3 (v4.0) | Medium |
| CVE-2026-85650 | Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel | trigger.dev | 5.3 (v4.0) | Medium |
| CVE-2026-49856 | @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization | jshookmcp | 4.3 (v3.1) | Medium |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | Clearfy Cache | 4.1 (v3.1) | Medium |
| CVE-2026-77351 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings | Wallos | 3.5 (v3.1) | Low |
| CVE-2023-3360 | Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection | Weaver Show Posts | 3.3 (v3.1) | Low |
| CVE-2025-13789 | ZenTao model.php makeRequest server-side request forgery | zentao | 2.1 (v4.0) | Low |
| CVE-2025-13809 | orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgery | orion-ops | 2.1 (v4.0) | Low |
| CVE-2026-82905 | sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery | chats | 2.1 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.