<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Server-Side Request Forgery (SSRF) (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ssrf.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ssrf-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Server-Side Request Forgery (SSRF) (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20230 – A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20230</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20230</strong></p>
  <p>A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.  This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit thi…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49120 – Medplum before 5.1.14 contains a server-side request forgery vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49120</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49120</strong></p>
  <p>Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unauthorized internal network requests by creating FHIR Subscription resources with arbitrary endpoint URLs. Attackers can point subscription endpoints at internal addresses such as cloud instance metadata services, internal databases, or container orche…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49139 – Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49139</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49139</strong></p>
  <p>Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subse…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10287 – A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10287</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10287</strong></p>
  <p>A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10280 – A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10280</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10280</strong></p>
  <p>A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP API Call Endpoint. The manipulation of the argument serverBaseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48555 – Spatie Laravel Media Library before version 11.23.0 contains a server-side reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48555</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48555</strong></p>
  <p>Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44285 – FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44285</guid>
    <pubDate>Fri, 29 May 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44285</strong></p>
  <p>FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploiting an incomplete fix in the dataset preview endpoint /api/core/dataset/file/getPreviewChunks when…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49372 – In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49372</guid>
    <pubDate>Fri, 29 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49372</strong></p>
  <p>In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10107 – MoviePilot v2 contains a server-side request forgery vulnerability in the image ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10107</guid>
    <pubDate>Fri, 29 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10107</strong></p>
  <p>MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token cookie and a URL whose domain matches the assembled allowlist. Attackers can bypass internal network protections because the SecurityUtils.is_safe_url function performs only domain-membership checking without blo…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10068 – A flaw has been found in Shibby Tomato 1.28. The affected element is the functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10068</guid>
    <pubDate>Fri, 29 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10068</strong></p>
  <p>A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45609 – mcp-security provides Security and Authorization support for Model Context Proto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45609</guid>
    <pubDate>Fri, 29 May 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45609</strong></p>
  <p>mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for OAuth-related discovery and metadata without verifying if the targets are malicious or inter…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42398 – Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42398</guid>
    <pubDate>Thu, 28 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42398</strong></p>
  <p>Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45373 – CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, althou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45373</guid>
    <pubDate>Thu, 28 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45373</strong></p>
  <p>CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in‌‌ URL‌ as http://[::1], the SSRF defenses do not work. This vulnerability is fixed in 0.8.26.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45310 – CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45310</guid>
    <pubDate>Thu, 28 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45310</strong></p>
  <p>CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the HTTP client (reqwest) is configured to automatically follow up to 5 redirects (reqw…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44797 – Nautobot is a Network Source of Truth and Network Automation Platform. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44797</guid>
    <pubDate>Thu, 28 May 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44797</strong></p>
  <p>Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48146 – Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48146</guid>
    <pubDate>Wed, 27 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48146</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was not applied to the OAuth2 t…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45717 – Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45717</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45717</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /api/datasources/:datasourceId). Every authenticated Budibase app user with the BASIC built-in role o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45061 – Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45061</guid>
    <pubDate>Wed, 27 May 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45061</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a single substring check: url.includes(".tar.gz"). Any URL containing .tar.gz anywhere in the string — in the path, query string, or fragment — passes this check. The URL then proceeds directly to fetchWithBlacklist() with no further validation of host…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44971 – GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44971</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44971</strong></p>
  <p>GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by G…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9312 – A server-side request forgery (SSRF) vulnerability was identified in GitHub Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9312</guid>
    <pubDate>Wed, 27 May 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9312</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potent…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2264 – A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2264</guid>
    <pubDate>Tue, 26 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2264</strong></p>
  <p>A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.  For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45082 – Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forger...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45082</guid>
    <pubDate>Tue, 26 May 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45082</strong></p>
  <p>Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward internal/private network destinations, these protections could be bypassed through crafted HTTP red…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48843 – Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48843</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48843</strong></p>
  <p>Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9372 – A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9372</guid>
    <pubDate>Sun, 24 May 2026 11:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9372</strong></p>
  <p>A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early thro…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3515 – A vulnerability in the `GitHubRepository` block of the `prefect-github` integrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3515</guid>
    <pubDate>Sun, 24 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3515</strong></p>
  <p>A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, lead…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39965 – TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39965</guid>
    <pubDate>Fri, 22 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39965</strong></p>
  <p>TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl() to block private IPs and cloud metadata hostnames. However, the HTTP clients (ky and fetch) follow 302 redirects without re-validating the redirect destination. An authenticated user can point a bot…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34207 – TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34207</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34207</strong></p>
  <p>TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It does not resolve DNS before allowing the request. As a result, a hostname such as ssrf-repro.example that resolves to 127.0.0.1, 169.254.169.254, or RFC1918/private space passes validation and is late…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33712 – Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview cha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33712</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33712</strong></p>
  <p>Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch function exposed inside the isolated-vm sandbox calls Node.js native fetch without the SSRF valida…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47358 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47358</guid>
    <pubDate>Tue, 19 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47358</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticate…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47357 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47357</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47357</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-g…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47356 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47356</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47356</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30118 – scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30118</guid>
    <pubDate>Tue, 19 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30118</strong></p>
  <p>scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentication cookies and headers exposure and possible privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31910 – Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.

This issue af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31910</guid>
    <pubDate>Tue, 19 May 2026 10:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31910</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29226 – Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29226</guid>
    <pubDate>Tue, 19 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29226</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8768 – A vulnerability was found in vercel ai up to 3.0.97. The affected element is the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8768</guid>
    <pubDate>Sun, 17 May 2026 23:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8768</strong></p>
  <p>A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8725 – A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8725</guid>
    <pubDate>Sun, 17 May 2026 02:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8725</strong></p>
  <p>A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about th…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45338 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45338</guid>
    <pubDate>Fri, 15 May 2026 22:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45338</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). The function fetches arbitrary URLs from OAuth picture claims without applying validate_url(), allowing an attacker to force the server to make HTTP…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45400 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45400</guid>
    <pubDate>Fri, 15 May 2026 21:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45400</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability. This vulnerability is fixed in 0.9.5.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42595 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42595</guid>
    <pubDate>Thu, 14 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42595</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point Chromium at any internal IP — including loopback, RFC 1918 ranges, and cloud metadata endpoints — and r…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42591 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42591</guid>
    <pubDate>Thu, 14 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42591</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42281 – MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42281</guid>
    <pubDate>Thu, 14 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42281</strong></p>
  <p>MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (**V…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44439 – PlaywrightCapture is a simple replacement for splash using playwright. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44439</guid>
    <pubDate>Wed, 13 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44439</strong></p>
  <p>PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the capture process open file:// URLs or request resources hosted on private, loopbac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44578 – Next.js is a React framework for building full-stack web applications. From 13.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44578</guid>
    <pubDate>Wed, 13 May 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44578</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44015 – Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44015</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44015</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and ena…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44232 – DSSRF is a Node.js library that provides a wide range of utilities and advanced ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44232</guid>
    <pubDate>Tue, 12 May 2026 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44232</strong></p>
  <p>DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.3.0, every IPv6 category bypasses is_url_safe. This vulnerability is fixed in 1.3.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-791</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34647 – Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34647</guid>
    <pubDate>Tue, 12 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34647</strong></p>
  <p>Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue requires user interaction in that a victim must…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43929 – ssrfcheck is a library that checks if a string contains a potential SSRF attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43929</guid>
    <pubDate>Tue, 12 May 2026 18:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43929</strong></p>
  <p>ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. http://[::ffff:127.0.0.1]/). The WHATWG URL parser built into Node.js silently normalizes the IPv4 notation inside the brackets to compressed hex form (…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42141 – Xibo is an open source digital signage platform with a web content management sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42141</guid>
    <pubDate>Tue, 12 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42141</strong></p>
  <p>Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43993 – JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-securit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43993</guid>
    <pubDate>Tue, 12 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43993</strong></p>
  <p>JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, resulting in an SSRF vulnerability. This vulnerability is fixed in 0.x.y-security-1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30810 – Server-Side Request Forgery vulnerability allows Privilege Escalation via API Ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30810</guid>
    <pubDate>Tue, 12 May 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30810</strong></p>
  <p>Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42260 – Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42260</guid>
    <pubDate>Tue, 12 May 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42260</strong></p>
  <p>Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43884 – WWBN AVideo is an open source video platform. In versions up to and including 29...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43884</guid>
    <pubDate>Mon, 11 May 2026 22:22:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43884</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsync.json.php and objects/EpgParser.php) in AVideo call isSSRFSafeURL() to validate user-supplied URLs, then fetch them using bare file_get_contents() without disabling PHP's automatic redirect following. An attacker can supply a URL pointing to a server they control that returns a…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45001 – OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-fac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45001</guid>
    <pubDate>Mon, 11 May 2026 18:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45001</strong></p>
  <p>OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/TLS, hook routing, MCP server configuration, SSRF policy, and filesystem hardening. A prompt-injected model with access to the owner-only gateway tool can persis…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2393 – A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2393</guid>
    <pubDate>Mon, 11 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2393</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter without validation, and the `_send_webhook_request()` function in `mlflow/webhooks/delivery.py` sends HTTP POST requests to this attacker-controlled URL. This allows an authenticated attacker to force…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44313 – Linkwarden is a self-hosted, open-source collaborative bookmark manager to colle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44313</guid>
    <pubDate>Sat, 09 May 2026 00:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44313</strong></p>
  <p>Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the fetchTitleAndHeaders function allows authenticated users to make arbitrary HTTP requests to internal services due to insufficient URL validation that only checks for "http://" or "https://" prefixes. T…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42339 – New API is a large language mode (LLM) gateway and artificial intelligence (AI) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42339</guid>
    <pubDate>Fri, 08 May 2026 23:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42339</strong></p>
  <p>New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular (non-admin) user holding any valid API token can send a multimodal request to /v1/chat/completions…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44694 – n8n-MCP is an MCP server that provides AI assistants access to n8n node document...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44694</guid>
    <pubDate>Fri, 08 May 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44694</strong></p>
  <p>n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authenticated server-side request forgery vulnerability affecting the webhook trigger tools, the n8n API client (N8N_API_URL), and per-request URLs supplied via the x-n8n-url header in multi-tenant HTTP mode. This issue has be…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42353 – i18next-http-middleware is a middleware to be used with Node.js web frameworks l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42353</guid>
    <pubDate>Fri, 08 May 2026 16:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42353</strong></p>
  <p>i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languages, namespaces, …) without any sanitization. Depending on which backend is configured, the unvalida…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44335 – PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44335</guid>
    <pubDate>Fri, 08 May 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44335</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42261 – PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42261</guid>
    <pubDate>Fri, 08 May 2026 04:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42261</strong></p>
  <p>PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/skills/fetch-remote that fetches a user-supplied URL server-side and reflects the response body (up to 5 MB) back to the caller. The SSRF protection in apps/web/src/utils/remote-http.ts (isPrivateIPv6)…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8034 – A server-side request forgery (SSRF) vulnerability was identified in the GitHub ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8034</guid>
    <pubDate>Thu, 07 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8034</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP request library. The hostname validation used a different URL parser than the request library, enabling a crafted URL to pass validation while directing th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41105 – Server-side request forgery (ssrf) in Azure Notification Service allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41105</guid>
    <pubDate>Thu, 07 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41105</strong></p>
  <p>Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42449 – n8n-MCP is an MCP server that provides AI assistants access to n8n node document...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42449</guid>
    <pubDate>Thu, 07 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42449</strong></p>
  <p>n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstanceContext()), the synchronous URL validator in SSRFProtection.validateUrlSync() had no IPv6 checks. IPv4-mapped IPv6 addresses such as http://[::ffff…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41688 – Wallos is an open-source, self-hostable personal subscription tracker. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41688</guid>
    <pubDate>Thu, 07 May 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41688</strong></p>
  <p>Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS rebinding TOCTOU window. At time of publication, there are no publicly available patches.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41654 – Weblate is a web based localization tool. Prior to version 5.17.1, an authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41654</guid>
    <pubDate>Thu, 07 May 2026 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41654</strong></p>
  <p>Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed s…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41644 – monetr is a budgeting application for recurring expenses. Prior to version 1.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41644</guid>
    <pubDate>Thu, 07 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41644</strong></p>
  <p>monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lunch Flow integration allowed any authenticated user on a self-hosted instance to cause the monetr server to issue HTTP GET requests to arbitrary URLs supplied by the caller, with the response body from non-200 upstream responses reflected back in the…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44116 – OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44116</guid>
    <pubDate>Wed, 06 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44116</strong></p>
  <p>OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43580 – OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43580</guid>
    <pubDate>Wed, 06 May 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43580</strong></p>
  <p>OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit flows, can bypass post-action security checks to execute unauthorized navigation.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43576 – OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43576</guid>
    <pubDate>Wed, 06 May 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43576</strong></p>
  <p>OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not properly validated, enabling attackers to redirect connections to arbitrary hosts and perform SSRF-style attacks.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41936 – Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41936</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41936</strong></p>
  <p>Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the applicati…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20035 – A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20035</guid>
    <pubDate>Wed, 06 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20035</strong></p>
  <p>A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device.  This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39383 – Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39383</guid>
    <pubDate>Tue, 05 May 2026 21:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39383</strong></p>
  <p>Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The FilterDeadline function in filter.go is intended to gate outbound URLs, but when both the allow-list…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34084 – PhpSpreadsheet is a library for reading and writing spreadsheet files. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34084</guid>
    <pubDate>Tue, 05 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34084</strong></p>
  <p>PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ssh2.sftp://) that passes the is_file() check in File::asser…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33975 – Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33975</guid>
    <pubDate>Tue, 05 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33975</strong></p>
  <p>Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g., ::ffff:169.254.169.254 becomes ::ffff:a9fe:a9fe), but the isPrivateIp utility only recog…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43573 – OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43573</guid>
    <pubDate>Tue, 05 May 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43573</strong></p>
  <p>OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43527 – OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43527</guid>
    <pubDate>Tue, 05 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43527</strong></p>
  <p>OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by default. Attackers can exploit this misconfiguration to access internal services or metadata endpoints through browser-driven requests.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43526 – OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43526</guid>
    <pubDate>Tue, 05 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43526</strong></p>
  <p>OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbitrary content. Attackers can exploit this by providing malicious media URLs that trigger SSRF requests, with fetched bytes subsequently re-uploaded through the channel.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42439 – OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42439</guid>
    <pubDate>Tue, 05 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42439</strong></p>
  <p>OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action endpoint to perform unauthorized tab navigation operations.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42436 – OpenClaw before 2026.4.14 contains an improper access control vulnerability in b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42436</guid>
    <pubDate>Tue, 05 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42436</strong></p>
  <p>OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigation. Authenticated callers can bypass SSRF restrictions to expose internal or disallowed page content by exploiting route-driven navigation without proper policy re-validation.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40682 – XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40682</guid>
    <pubDate>Mon, 04 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40682</strong></p>
  <p>XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor   Versions Affected: before 2.5.9, before 3.0.0-M3   Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6229 – The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6229</guid>
    <pubDate>Sat, 02 May 2026 08:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6229</strong></p>
  <p>The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter, and the subsequent use of these URLs in fopen() calls without blocking interna…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7049 – The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7049</guid>
    <pubDate>Sat, 02 May 2026 06:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7049</strong></p>
  <p>The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 via the scan_video. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The S…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7417 – A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7417</guid>
    <pubDate>Wed, 29 Apr 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7417</strong></p>
  <p>A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of the argument media_paths results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41914 – OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41914</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41914</strong></p>
  <p>OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41912 – OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41912</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41912</strong></p>
  <p>OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7223 – A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7223</guid>
    <pubDate>Tue, 28 Apr 2026 04:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7223</strong></p>
  <p>A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. Th…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7221 – A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7221</guid>
    <pubDate>Tue, 28 Apr 2026 04:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7221</strong></p>
  <p>A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.17.…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7178 – A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7178</guid>
    <pubDate>Mon, 27 Apr 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7178</strong></p>
  <p>A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project wa…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7177 – A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7177</guid>
    <pubDate>Mon, 27 Apr 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7177</strong></p>
  <p>A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early th…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7158 – A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7158</guid>
    <pubDate>Mon, 27 Apr 2026 21:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7158</strong></p>
  <p>A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This pro…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7147 – A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7147</guid>
    <pubDate>Mon, 27 Apr 2026 19:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7147</strong></p>
  <p>A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was i…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7146 – A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7146</guid>
    <pubDate>Mon, 27 Apr 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7146</strong></p>
  <p>A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed publicly a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7094 – A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7094</guid>
    <pubDate>Mon, 27 Apr 2026 07:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7094</strong></p>
  <p>A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7065 – A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7065</guid>
    <pubDate>Mon, 27 Apr 2026 00:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7065</strong></p>
  <p>A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload API. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7025 – A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7025</guid>
    <pubDate>Sun, 26 Apr 2026 08:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7025</strong></p>
  <p>A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted ea…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41361 – OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41361</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41361</strong></p>
  <p>OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by crafting URLs targeting internal or non-routable IPv6 addresses to bypass SSRF protections.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35431 – Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35431</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35431</strong></p>
  <p>Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32210 – Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32210</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32210</strong></p>
  <p>Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26150 – Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26150</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26150</strong></p>
  <p>Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41272 – Flowise is a drag &amp; drop user interface to build a customized large language mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41272</guid>
    <pubDate>Thu, 23 Apr 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41272</strong></p>
  <p>Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the allow/deny lists via DNS Rebinding (Time-of-Check Time-of-Use) or by exploiting the default configurati…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41272">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
