Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 605— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 5.5
FetchURL SSRF Bypass via DNS Rebinding and Redirects Vulnerability Analysis
github.com · 2026-07-27

### Vulnerability Overview This vulnerability involves SSRF (Server-Side Request Forgery) bypasses and DNS rebinding issues in the `FetchURL` tool. The `FetchURL` tool originally relied on a static ho…

Read more
Printcart Web to Print for WooCommerce <2.5.3 Unauthenticated Arbitrary File Read and SSRF (CVE-2025-15662)
wpscan.com · 2026-07-27

# Printcart Web to Print Product Designer for WooCommerce root:x:0:0:... # Use url=file:///var/www/html/wp-config.php to retrieve DB credentials and auth salts. # 3) Server-Side Request Forgery target…

Read more
CVSS 6.3
openlaw-cn SSRF bypass to loopback/private targets via /act interaction
github.com · 2026-07-26

### Vulnerability Overview **Title**: Browser interaction-driven navigation bypasses `browser.ssrPolicy` and reaches loopback/private targets #562 **Description**: In `openlaw-cn`, the authenticated b…

Read more
CVSS 4.1
Shopware SSRF in Media Endpoint Bypasses IP Validation
github.com · 2026-07-24

### Vulnerability Overview **Vulnerability Name**: SSRF in Media External-Link Endpoint Bypasses IP Validation **Description**: In Shopware’s `/api/action/media/external-link` endpoint, authenticated …

Read more
LLM CTF Challenge Bypass: SSRF and Non-Expected Path Analysis in Qwen3, Grok, DeepSeek
projectdiscovery.io · 2026-07-22

### Vulnerability Overview - **Vulnerability Name**: Not explicitly named; involves multiple case studies. - **Vulnerability Description**: - **Qwen3.6-27B**: When attempting to solve challenges, the …

Read more
CVSS 7.1
CC-Tweaked SSRF Bypass via NAT64 Prefix: Vulnerability, POC, and Fix
github.com · 2026-07-22

# SSRF Protection Bypass with NAT64 ## Vulnerability Overview The HTTP API (`http.request`, `http.request`, `http.websocket`) in CC-Tweaked is designed to block requests to private network ranges to p…

Read more
CVSS 8.2
SSRF Vulnerability in visit_page Tool via Cloud Metadata Access
github.com · 2026-07-22

### Vulnerability Overview **Vulnerability Name**: SSRF via `visit_page` **Vulnerability Type**: Server-Side Request Forgery (SSRF) **Vulnerability Description**: The `visit_page` utility loads a user…

Read more
Premium intel
CVSS 8.6
Unauthenticated SSRF and CORS Bypass in Verba RAG Application
github.com · 2026-07-22

### Vulnerability Overview #### Vulnerability 1: Unauthenticated SSRF in Verba WebSocket Import Endpoint (HTMLReader) - **Details**: An unauthenticated Server-Side Request Forgery (SSRF) vulnerability…

Read more
CVSS 8.6
Pre-Auth SSRF Bypass via Redirect in OpenAI-Compatible Chat Endpoint (POC & Fix)
github.com · 2026-07-22

### Vulnerability Overview An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in OpenAI-compatible chat endpoints, specifically within the `image_url` parameter. This vulnerabi…

Read more
CVSS 6.5
Blind SSRF in FlaskBB get_image_info() allowing AWS metadata access
github.com · 2026-07-22

### Vulnerability Overview **Vulnerability Name**: SSRF in get_image_info() via unrestricted avatar URL (CWE-918) **Vulnerability Description**: There is a Server-Side Request Forgery (SSRF) vulnerabi…

Read more
SSRF Bypass & Data Exfiltration in next-ai-draw-io via Provider Spoofing
github.com · 2026-07-22

### Vulnerability Overview **Vulnerability Name**: SSRF Guard Bypass via EdgeOne/Ollama Provider Spoofing in next-ai-draw-io #749 **Vulnerability Type**: CWE-918: Server-Side Request Forgery (SSRF) **…

Read more
CVSS 5.5
PraisonAI spider_tools SSRF Protection Bypass via Alternate Loopback Host Encodings (CVE-2024-47390)
github.com · 2026-07-22

### Vulnerability Overview **Vulnerability Name**: PraisonAI `spider_tools` SSRF protection bypass via alternate loopback host encodings **Vulnerability Description**: The URL validation functionality…

Read more
USN-8572-1: Wget SSRF Vulnerability Fix in FTP Passive Mode
ubuntu.com · 2026-07-20

# USN-8572-1: Wget vulnerability ## Vulnerability Summary Wget does not properly validate the IP address provided when operating in FTP passive mode. A remote attacker controlling a malicious FTP serv…

Read more
CVSS 7.7
SSRF Fix: Webhook & ClickHouse Proxy bypassing private IP checks and error info leak
github.com · 2026-07-21

### Vulnerability Overview This vulnerability involves two main security issues: 1. **Webhook SSRF (POST /webhooks/test)**: - **Issue**: `validateWebhookUrl` only blocks hostnames extracted from `CLIC…

Read more
CVSS 7.7
Hugnin SSRF via Scenario Import: Internal Network Scanning and Cloud Metadata Access
github.com · 2026-07-21

### Vulnerability Overview **Vulnerability Name**: SSRF via Scenario Import URL #3679 **Vulnerability Type**: Server-Side Request Forgery (SSRF) **Vulnerability Description**: - An attacker can cause …

Read more
CVSS 4.1
SurrealDB SSRF via JWKs URL: Hostname Allowlist Bypass to Private IP
github.com · 2026-07-20

### Vulnerability Overview **Vulnerability Name**: SSRF via JWKs URL — allow-listed hostname resolving to a private IP **Description**: When fetching JWT or record access method JWKs documents, Surrea…

Read more
CVSS 6.3
CordysCRM v1.4.1 SSRF Vulnerability Analysis and POC via mkAddress Parameter
github.com · 2026-07-19

### Vulnerability Overview **Vulnerability Name**: CordysCRM v1.4.1 SSRF in /organization/settings/third-party/edit via mkAddress Parameter #2685 **Vulnerability Type**: Server-Side Request Forgery (S…

Read more
CVSS 6.3
GoCrawl web_fetch SSRF Bypass via Special IPv4 Range 198.18.0.0/15
github.com · 2026-07-19

### Vulnerability Overview **Title**: GoCrawl web_fetch SSRF Protection Bypass via Misuse of Special-Use IPv4 Range 198.18.0.0/15 **Description**: GoCrawl's `web_fetch` tool exposes a Server-Side HTTP…

Read more
Premium intel
CVSS 7.3
SSRF vulnerability in rt-claw http_request tool (<=0.2.0) allowing loopback access
github.com · 2026-07-19

### Vulnerability Overview **Title**: [Security] http_request tool SSRF allows loopback and private-network HTTP access in rt-claw #139 **Description**: - **Vulnerability Type**: Server-Side Request F…

Read more
Premium intel
CVSS 5.8
SurrealDB SSRF Bypass via DNS Resolution of Deny-Net Flags
github.com · 2026-07-18

# SurrealDB Vulnerability Summary ## Overview - **Vulnerability Name**: Bypass of deny-net flags via DNS resolution - **CVE ID**: GHSA-m3c3-78fh-w3w7 - **Publication Date**: June 26, 2025 - **Severity…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.