Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 609— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 7.4
Fix SSRF Bypass in crawl_tools: Redirect Validation and Credential Stripping
github.com · 2026-07-14

### Vulnerability Overview This vulnerability involves bypassing SSRF (Server-Side Request Forgery) redirection during request fetching. Specifically, it manifests as a failure to properly prevent cre…

Read more
CVSS 7.4
SSRF Bypass via HTTP Redirect in crewai-tools Scrape Tools with POC
github.com · 2026-07-14

### Vulnerability Overview - **Vulnerability Name**: SSRF filter bypass via HTTP redirect (and DNS rebinding) in the crewai-tools scrape tools #6520 - **Vulnerability Type**: Server-Side Request Forge…

Read more
CVSS 7.4
CrewAI SSRF Bypass via Redirect in Scraping Tools with Fix POC
github.com · 2026-07-14

### Vulnerability Overview This vulnerability involves a Server-Side Request Forgery (SSRF) redirect bypass in the Scraper and URL-supported RAG loaders. Attackers can bypass initial URL validation by…

Read more
MISP html_to_markdown Module SSRF Vulnerability Patch: IPv4-Mapped IPv6 Bypass Analysis
github.com · 2026-07-13

### Vulnerability Overview This vulnerability involves an HTML Markdown SSRF (Server-Side Request Forgery) attack, bypassing security restrictions via IPv4-mapped IPv6 addresses. ### Scope of Impact -…

Read more
Premium intel
CVSS 8.5
PrisonAI web_crawl Crawl4AI Backend SSRF Bypass via DNS Rebinding
github.com · 2026-07-11

### Vulnerability Overview **Title**: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass **Description**: - **Summary**: DNS rebinding/redirect SSRF bypasses are not …

Read more
CVSS 5.8
Fix for SSRF bypass in IsInternalIP due to incomplete IPv6 transition mechanism detection
github.com · 2026-07-11

### Vulnerability Overview This vulnerability involves incomplete detection of IPv6 transition mechanisms in the `IsInternalIP()` function, leading to a flaw in SSRF (Server-Side Request Forgery) prot…

Read more
CVSS 5.8
mailpit SSRF fix follow-up: IPv6 bypass in link check API (CVE-2026-27808)
github.com · 2026-07-11

# Incomplete SSRF Protection Due to Unhandled IPv6 Forms in the Link Checking API (Follow-up to GHSA-mpf7-p9x7-96r3 / CVE-2026-27808) ## Vulnerability Overview This vulnerability involves incomplete S…

Read more
Premium intel
CVSS 8.2
9router CVE-2024-55641: Unauthenticated Proxy Access & SSRF via Host-header Spoofing
github.com · 2026-07-11

### Vulnerability Overview **Vulnerability Name**: Unauthenticated `/v1` proxy access in 9router@0.4.71 via `Host`-header spoofing → open AI relay + SSRF **Vulnerability Description**: - **Vulnerabili…

Read more
CVE-2025-54760: langroid SQLChatAgent pg_read_file SSRF Bypass
github.com · 2026-07-10

### Vulnerability Overview **SQLChatAgent dangerous function blacklist can be bypassed via quoted or schema-qualified `pg_read_file` calls** - **Vulnerability Description**: SQLChatAgent’s SQL injecti…

Read more
CVSS 6.3
PicoClaw web_fetch SSRF Protection Bypass via Environment Proxy
github.com · 2026-07-10

### Vulnerability Overview **Title**: PicoClaw web_fetch SSRF protection can be bypassed via environment-configured HTTP proxy #3078 **Description**: The `web_fetch` tool, enabled by default in PicoCl…

Read more
CVSS 7.7
SSRF Protection Bypass via Unresolved Hostname in Notification URLs (Pre-Auth/Low Priv)
github.com · 2026-07-10

### Vulnerability Overview **Vulnerability Name**: SSRF Protection Bypass via Unresolved Hostname in Notification URLs **Vulnerability Description**: The default SSRF protection configuration does not…

Read more
Premium intel
CVSS 8.0
Open WebUI Terminal Proxy Identity Forging and SSRF via Unvalidated Session ID
github.com · 2026-07-10

### Vulnerability Overview This vulnerability involves the terminal proxy forwarding a spoofable, integrity-unbound user identity to the upstream server. Specifically, in `backend/open_weblu/routers/t…

Read more
CVSS 4.3
Open-WebUI SSRF bypass via WEB_FETCH_FILTER_LIST logic flaw
github.com · 2026-07-10

### Vulnerability Overview - **Vulnerability ID**: #25949 - **Description**: In the `open-webui` project, the matching logic for `WEB_FETCH_FILTER_LIST` contains a flaw that allows certain malicious U…

Read more
CVSS 7.7
FastGPT SSRF Vulnerability Advisory: SwaggerParser $ref Bypass (CVE/High Severity)
github.com · 2026-07-08

### Vulnerability Overview **Vulnerability Name**: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard) **Vulnerability Description**: This vulnerabi…

Read more
Hugo SSRF via HTTP Redirect Bypass (CVE-2026-50134)
github.com · 2026-07-07

### Vulnerability Overview - **Vulnerability Name**: security.http.urls allow-list bypass via HTTP redirects - **CVE ID**: CVE-2026-50134 - **Severity**: Moderate - **Release Date**: May 28 ### Scope …

Read more
Hugo SSRF via security.http.urls bypass and patch analysis in resources.GetRemote
github.com · 2026-07-07

### Vulnerability Overview This vulnerability involves insufficient validation of `security.http.urls`, which may lead to resources being redirected to unauthorized servers. Specifically, `resources.G…

Read more
CVSS 6.3
SSRF Vulnerability in mcp-wiki MCP Server: read_wikipedia_article Tool URL Validation Bypass and PoC
github.com · 2026-07-05

### Vulnerability Overview - **Vulnerability Name**: SSRF in `read_wikipedia_article` via Insufficient URL Validation #34 - **Vulnerability Type**: Server-Side Request Forgery (SSRF) - **Root Cause**:…

Read more
CVSS 8.5
IBM WebSphere Liberty SSRF/Authorization Bypass Vulnerability (CVE-2026-11714) Advisory
www.ibm.com · 2026-07-05

### Vulnerability Overview - **Vulnerability Name**: IBM WebSphere Application Server Liberty Authorization Bypass Vulnerability - **CVE ID**: CVE-2026-11714 - **Description**: IBM WebSphere Applicati…

Read more
Premium intel
CVSS 9.6
Gitea fix SSRF: Block reserved IP ranges from external/private filters to prevent internal access
github.com · 2026-07-04

### Vulnerability Overview - **Vulnerability Title**: fix(hostmatcher): block reserved IP ranges from external/private filters (#38039) - **Issue Number**: #38059 - **Status**: Merged - **Author**: bi…

Read more
Premium intel
CVSS 8.5
Buddibase SSRF DNS Rebinding Bypass Vulnerability Advisory
github.com · 2026-07-02

### Vulnerability Overview **Title**: Potential SSRF DNS rebinding bypass in outbound fetch validation **Description**: - **Summary**: Users with automation privileges can bypass Buddibase's SSRF blac…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.