Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Allura CRITICAL 9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend…

No fix yet
Fix from $5,750 2026-08-11
Traffic Server HIGH 7.5
CVE-2026-58189

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traf…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Syncope HIGH 8.1
CVE-2026-62418

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue af…

Fix: 4.0.7 / 4.1.2+
Fix from $1,950 2026-07-20
Gravitino MEDIUM 6.5
CVE-2026-49876

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp…

Fix: 1.3.0+
Fix from $1,600 2026-07-13
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel HIGH 7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Fesod MEDIUM 5.3
CVE-2026-49328

Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attacke…

Fix: 2.0.2+
Fix from $1,600 2026-06-01
Flink Kubernetes Operator MEDIUM 6.5
CVE-2026-40564

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The Flink…

Fix: 1.15.0+
Fix from $1,600 2026-05-26
Shiro MEDIUM 5.4
CVE-2026-44598

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. …

Fix: 2.1.1+
Fix from $1,600 2026-05-25
Ofbiz HIGH 7.5
CVE-2026-31910

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz HIGH 7.3
CVE-2026-29226

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06.…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Neethi HIGH 7.2
CVE-2026-42404

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an appli…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Skywalking Mcp HIGH 7.1
CVE-2026-34476

Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are re…

Fix: 0.2.0+
Fix from $1,950 2026-04-13
HTTP Server HIGH 7.5
CVE-2025-59775

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to po…

Fix: 2.4.66+
Fix from $1,950 2025-12-05
Kylin HIGH 7.3
CVE-2025-61735

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as…

Fix: 5.0.3+
Fix from $1,950 2025-10-02
Eventmesh MEDIUM 6.3
CVE-2024-39954

CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse…

Fix: 1.12.0+
Fix from $1,600 2025-08-20
HTTP Server HIGH 7.5
CVE-2024-43394

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or …

Fix: 2.4.64+
Fix from $1,950 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-43204

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
Kafka HIGH 7.5
CVE-2025-27817EPSS 65%

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for …

Fix: 3.9.1+
Fix from $1,950 2025-06-10
Hertzbeat MEDIUM 6.5
CVE-2024-56736

Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are rec…

Fix: 1.7.0+
Fix from $1,600 2025-04-16
Kylin MEDIUM 6.5
CVE-2024-48944

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d…

Fix: 5.0.2+
Fix from $1,600 2025-03-27
Druid MEDIUM 5.4
CVE-2025-27888

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…

Fix: 31.0.2+
Fix from $1,600 2025-03-20
Ranger CRITICAL 9.1
CVE-2024-45479

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger…

Fix: 2.5.0+
Fix from $2,300 2025-01-21
Ofbiz CRITICAL 9.8
CVE-2024-47208

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.17+
Fix from $2,300 2024-11-18
Ofbiz CRITICAL 9.8
CVE-2024-45507EPSS 93%

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.16+
Fix from $2,300 2024-09-04
Iotdb Workbench HIGH 7.3
CVE-2024-36448

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbenc…

Mitigation only
Fix from $1,950 2024-08-05
Cxf CRITICAL 9.1
CVE-2024-29736

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…

Fix: 3.5.9 / 3.6.4+
Fix from $2,300 2024-07-19