Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 601— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 7.3
Fix SSRF bypass in web_fetch via ISATAP IPv6 literals embedding private IPv4
github.com · 2026-07-18

### Vulnerability Overview - **Vulnerability Title**: fix(web): block private IPv4 embeds in ISATAP literals #3143 - **Vulnerability Description**: Addresses an SSRF protection bypass in `web_fetch` a…

Read more
CVSS 7.3
PicoClaw web_fetch SSRF guard bypass via ISATAP IPv6 literals
github.com · 2026-07-18

### Vulnerability Overview **Title**: PicoClaw web_fetch SSRF guard bypass via ISATAP IPv6 literals embedding loopback/private IPv4 **Description**: PicoClaw's `web_fetch` tool attempts to block reque…

Read more
CVSS 4.9
Statamic SSRF Fix: RemoteUrlValidator class to prevent redirect attacks to internal IPs
github.com · 2026-07-18

### Vulnerability Overview This vulnerability addresses the hardening of remote URL validation, specifically preventing redirect attacks and internal address access when processing HTTP requests. By i…

Read more
CVSS 6.3
Auth SSRF in AstrBot Plugin Update Endpoint via download_url/proxy
gist.github.com · 2026-07-18

### Vulnerability Overview **Title**: Authenticated Server-Side Request Forgery (SSRF) via User-Controlled `download_url`, `download_urls`, and `proxy` in AstrBot Plugin Update Endpoint **Description*…

Read more
CVSS 4.3
Dendrite Vulnerability Advisory: IDOR, SSRF, and Authorization Bypass
github.com · 2026-07-18

The following is a summary of the key vulnerability information based on the provided web page screenshots: --- ### Vulnerability Overview 1. **IDOR in POST /account/3pid/delete allows any authenticat…

Read more
CVSS 6.1
Apify actors-mcp-server URL Validation Bypass Leading to SSRF and Prompt Injection (CVE-xxxx)
github.com · 2026-07-17

### Vulnerability Overview In the `fetch-apify-docs` tool, URL validation relies on `String.startsWith()` instead of proper URL hostname comparison. This allows attackers to bypass the domain whitelis…

Read more
CVSS 8.6
stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass
www.vulncheck.com · 2026-07-17

# stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass ## Vulnerability Overview In stoatchat versions prior to 0.14.0, a Server-Side Request Forgery (SSRF) vulnerability allows unauthenticated a…

Read more
Premium intel
CVSS 6.5
WeKan v9.32 Security Advisory: SSRF, Privilege Escalation, Auth Bypass, and More
github.com · 2026-07-16

### Vulnerability Overview WeKan v9.32 fixes multiple critical security vulnerabilities, including Server-Side Request Forgery (SSRF), authorization bypass, privilege escalation, unauthorized access, …

Read more
CVSS 6.4
SSRF Vulnerability Fix: Missing AWS Region Validation Causing Upstream URL Reflection
github.com · 2026-07-16

### Vulnerability Overview This vulnerability involves a failure to correctly reject non-AWS region values during region validation to prevent SSRF (Server-Side Request Forgery). This can lead to the …

Read more
Premium intel
CVSS 9.6
better-auth v1.6.11 Patch: SSRF, OAuth Race Conditions, SCIM/SSO Privilege Escalation
github.com · 2026-07-16

### Vulnerability Overview In version 1.6.11 of `better-auth`, several security vulnerabilities were addressed, primarily including: 1. **Invitation Takeover Vulnerability**: Fixed by enabling `requir…

Read more
CVSS 5.8
Vaultwarden SSRF Vulnerability: Decimal/Hex IP Bypass via Icon Endpoint
github.com · 2026-07-16

### Vulnerability Overview **Vulnerability Name**: Server-Side Request Forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass **Vulnerability Description**: - This vulnerability allows attackers…

Read more
Premium intel
CVSS 7.7
Directus <= 12.0.0 SSRF Protection Bypass via 0.0.0.0 (CVE-2026-6335)
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves an SSRF (Server-Side Request Forgery) protection bypass in the Directus file import feature. Attackers can bypass existing SSRF protections by us…

Read more
FastGPT SSRF Vulnerability Bypass via HTTP Redirect and Fix Guide
github.com · 2026-07-15

### Vulnerability Overview The shared SSRF guard in FastGPT only validates the initial URL before following redirects. Attackers can exploit HTTP redirects to bypass SSRF protection and access blocked…

Read more
symfony/polyfill-intl-idn Punycode Validation Bypass Leading to SSRF Risk
github.com · 2026-07-15

# symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence ## Vulnerability Overview `symfony/polyfill-intl-idn` provides a user-space implement…

Read more
Symfony SSRF Bypass via IPv6 Transition Forms (CVE-2024-48736) Advisory
github.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient - **CVE ID**…

Read more
Symfony IpUtils Private IP Check Defect Allows SSRF Bypass
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves the handling of IPv6 addresses within the Symfony framework. Specifically, the `IpUtils::PRIVATE_SUBNETS` list does not include IPv4-compatible I…

Read more
CVSS 8.6
Unauthenticated SSRF in Monsta FTP via isBlockedIP bypass, with POC
www.vulncheck.com · 2026-07-15

### Vulnerability Overview An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Monsta FTP version 2.14.4. This vulnerability allows attackers to upload user-provided URLs to …

Read more
CVSS 7.2
Roundcube SSRF Bypass via Local URL Filtering Fix
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves bypassing SSRF (Server-Side Request Forgery) attacks through specific local address URLs. This update addresses two new cases to prevent such att…

Read more
CVSS 6.3
GoClaw create_video SSRF Bypass via Provider-returned URLs Analysis
github.com · 2026-07-14

### Vulnerability Overview **Title**: Provider-returned video URLs in `create_video` bypass SSRF protections and allow internal network fetches #1199 **Description**: - **Vulnerability Type**: SSRF (S…

Read more
CVSS 7.4
Fix SSRF Bypass in crawl_tools: Redirect Validation and Credential Stripping
github.com · 2026-07-14

### Vulnerability Overview This vulnerability involves bypassing SSRF (Server-Side Request Forgery) redirection during request fetching. Specifically, it manifests as a failure to properly prevent cre…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.