Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-69223
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommend…
Allura
No fix yet
HIGH 7.5
CVE-2026-58189
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.
This issue affects Apache Traf…
Traffic Server
9.2.15 / 10.1.4+
HIGH 8.1
CVE-2026-62418
Low-privileged authenticated Server-Side Request Forgery (SSRF)
vulnerability in Apache Syncope via Connectors and Resources check.
This issue af…
Syncope
4.0.7 / 4.1.2+
MEDIUM 6.5
CVE-2026-49876
Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job temp…
Gravitino
1.3.0+
HIGH 7.5
CVE-2026-55994
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.18.3 / 4.21.0+
HIGH 7.5
CVE-2026-55993
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48203
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48205
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operatio…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46726
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49328
Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attacke…
Fesod
2.0.2+
MEDIUM 6.5
CVE-2026-40564
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.
The Flink…
Flink Kubernetes Operator
1.15.0+
MEDIUM 5.4
CVE-2026-44598
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.
…
Shiro
2.1.1+
HIGH 7.5
CVE-2026-31910
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrad…
Ofbiz
24.09.06+
HIGH 7.3
CVE-2026-29226
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.…
Ofbiz
24.09.06+
HIGH 7.2
CVE-2026-42404
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an appli…
Neethi
3.2.2+
HIGH 7.1
CVE-2026-34476
Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking MCP: 0.1.0.
Users are re…
Skywalking Mcp
0.2.0+
HIGH 7.5
CVE-2025-59775
Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off allows to po…
HTTP Server
2.4.66+
HIGH 7.3
CVE-2025-61735
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as…
Kylin
5.0.3+
MEDIUM 6.3
CVE-2024-39954
CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse…
Eventmesh
1.12.0+
HIGH 7.5
CVE-2024-43394
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via
mod_rewrite or …
HTTP Server
2.4.64+
HIGH 7.5
CVE-2024-43204
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an…
HTTP Server
2.4.64+
HIGH 7.5
CVE-2025-27817EPSS 65%
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for …
Kafka
3.9.1+
MEDIUM 6.5
CVE-2024-56736
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat (incubating): before 1.7.0.
Users are rec…
Hertzbeat
1.7.0+
MEDIUM 6.5
CVE-2024-48944
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/d…
Kylin
5.0.2+
MEDIUM 5.4
CVE-2025-27888
Severity: medium (5.8) / important
Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
Druid
31.0.2+
CRITICAL 9.1
CVE-2024-45479
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger…
Ranger
2.5.0+
CRITICAL 9.8
CVE-2024-47208
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.17+
CRITICAL 9.8
CVE-2024-45507EPSS 93%
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apac…
Ofbiz
18.12.16+
HIGH 7.3
CVE-2024-36448
** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench.
This issue affects Apache IoTDB Workbenc…
Iotdb Workbench
Mitigation only
CRITICAL 9.1
CVE-2024-29736
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…
Cxf
3.5.9 / 3.6.4+