CWE-918 服务端请求伪造(SSRF) 类弱点 1540 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-918 服务端请求伪造(SSRF)是一种允许攻击者诱导服务器发起恶意请求的漏洞。当服务器接收外部提供的 URL 并据此获取内容时,若未严格校验目标地址,攻击者可构造请求访问内网资源或探测内部服务,从而绕过防火墙限制。开发者应实施严格的白名单机制,限制协议类型,禁用重定向,并对所有输入进行深度验证,确保请求仅能访问预期的合法外部资源,从而有效防御此类攻击。
$url = $_GET['url']; # User-controlled input # Fetch the content of the provided URL $response = file_get_contents($url); echo $response;# Define allowed URLs (or domains) $allowed_urls = [ 'https://example.com/data.json', 'https://api.example.com/info', ]; # Get the user-provided URL $url = $_GET['url'] ?? ''; # Validate against allowed URLs if (!in_array($url, $allowed_urls)) { http_response_code(400); echo "Invalid or unauthorized URL."; exit; } # Fetch content safely $response = @file_get_contents($url); if ($response === false) { http_response_code(500); echo "Failed to fetch content."; exit; } echo htmlspecialchars($response); # Escape output for safety| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-8193 | Akaunting发票PDF渲染dompdf.php服务器端请求伪造漏洞 — Akaunting | 6.3 | Medium | 2026-05-09 |
| CVE-2026-44313 | LinkWarden 链接创建 SSRF 漏洞 — linkwarden | 9.1 | Critical | 2026-05-08 |
| CVE-2026-42352 | pygeoapi 代码问题漏洞 — pygeoapi | 8.6 | High | 2026-05-08 |
| CVE-2026-42346 | Gitroom Postiz 代码问题漏洞 — postiz-app | 6.5 | Medium | 2026-05-08 |
| CVE-2026-42339 | New API 代码问题漏洞 — new-api | 8.1AI | HighAI | 2026-05-08 |
| CVE-2026-44286 | FastGPT 代码问题漏洞 — FastGPT | 8.1AI | HighAI | 2026-05-08 |
| CVE-2026-44284 | FastGPT 代码问题漏洞 — FastGPT | 6.3 | Medium | 2026-05-08 |
| CVE-2026-42345 | FastGPT 代码问题漏洞 — FastGPT | 7.7 | High | 2026-05-08 |
| CVE-2026-42180 | Lemmy 代码问题漏洞 — lemmy | 6.3 | Medium | 2026-05-08 |
| CVE-2026-42181 | Lemmy 代码问题漏洞 — lemmy | 6.5 | Medium | 2026-05-08 |
| CVE-2026-44335 | PraisonAI 代码问题漏洞 — PraisonAI | 9.1AI | CriticalAI | 2026-05-08 |
| CVE-2026-41423 | Angular 代码问题漏洞 — angular | 9.1AI | CriticalAI | 2026-05-08 |
| CVE-2026-8034 | GitHub Enterprise Server 安全漏洞 — Enterprise Server | 8.2AI | HighAI | 2026-05-07 |
| CVE-2026-41105 | Microsoft Azure Notification Service 代码问题漏洞 — Azure Monitor Action Group notification system | 8.1 | High | 2026-05-07 |
| CVE-2026-42449 | n8n-MCP 代码问题漏洞 — n8n-mcp | 8.5 | High | 2026-05-07 |
| CVE-2026-41905 | FreeScout 代码问题漏洞 — freescout | 7.7 | High | 2026-05-07 |
| CVE-2026-8081 | CLI Proxy API 代码问题漏洞 — CLIProxyAPI | 6.3 | Medium | 2026-05-07 |
| CVE-2026-41688 | Wallos 代码问题漏洞 — Wallos | 7.7 | High | 2026-05-07 |
| CVE-2026-41687 | Wallos 代码问题漏洞 — Wallos | 4.3 | Medium | 2026-05-07 |
| CVE-2026-41413 | Istio 代码问题漏洞 — istio | 5.0 | Medium | 2026-05-07 |
| CVE-2026-42194 | Admidio 代码问题漏洞 — admidio | 6.8 | Medium | 2026-05-07 |
| CVE-2026-44117 | OpenClaw 代码问题漏洞 — OpenClaw | 5.8 | Medium | 2026-05-06 |
| CVE-2026-44116 | OpenClaw 代码问题漏洞 — OpenClaw | 8.6 | High | 2026-05-06 |
| CVE-2026-20035 | Cisco Unity Connection Web Inbox 代码问题漏洞 — Cisco Unity Connection | 7.2 | High | 2026-05-06 |
| CVE-2026-39383 | Gotenberg 代码问题漏洞 — gotenberg | 8.2 | - | 2026-05-05 |
| CVE-2026-35527 | Incus 代码问题漏洞 — incus | - | - | 2026-05-05 |
| CVE-2026-40280 | Gotenberg 代码问题漏洞 — gotenberg | 5.3 | - | 2026-05-05 |
| CVE-2026-33975 | Twenty 代码问题漏洞 — twenty | 9.1 | - | 2026-05-05 |
| CVE-2026-7412 | Eclipse BaSyx Java Server SDK 代码问题漏洞 — Eclipse BaSyx | 8.6 | High | 2026-05-05 |
| CVE-2026-43527 | OpenClaw 代码问题漏洞 — OpenClaw | 7.7 | High | 2026-05-05 |
CWE-918(服务端请求伪造(SSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 1540 条 CVE 漏洞。