Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 612— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 6.5
Microsoft Edge SSRF Vulnerability Advisory (CVE-2026-57987)
msrc.microsoft.com · 2026-07-04

### Vulnerability Overview - **Vulnerability Name**: Microsoft Edge (Chromium-based) Spoofing Vulnerability - **CVE ID**: CVE-2026-57987 - **Publication Date**: July 3, 2026 - **CVSS Score**: 6.5 / 5.…

Read more
CVSS 7.4
Microsoft Edge Chromium SSRF Spoofing Vulnerability CVE-2026-57993
msrc.microsoft.com · 2026-07-04

### Vulnerability Overview - **Vulnerability Name**: Microsoft Edge (Chromium-based) Spoofing Vulnerability - **CVE ID**: CVE-2026-57993 - **Publication Date**: July 3, 2026 - **CVSS Score**: 7.4 / 10…

Read more
CVSS 6.5
Gitea 1.25.4 SSRF via HTTP Redirect in Repository Migration
github.com · 2026-07-04

# SSRF via HTTP Redirect in Repository Migration ## Vulnerability Overview Gitea 1.25.4 contains a vulnerability during the validation of the initial URL provided to the repository migration endpoint …

Read more
CVSS 6.3
SSRF Vulnerability in Streamlit MCP Hostollama Server Tool with Fix
github.com · 2026-07-05

### Vulnerability Overview A Server-Side Request Forgery (SSRF) vulnerability exists in the `summarize_wikipedia_article` tool. The root cause is that the `url` parameter, when passed to Python's `req…

Read more
Apache Camel CVE-2026-48203 SSRF Vulnerability Advisory and Fix Guide
camel.apache.org · 2026-07-06

### Vulnerability Overview - **Vulnerability Name**: CVE-2026-48203 - **Severity**: Medium - **Description**: Apache Camel's `SolrParam` and `SolrField` exchange headers use non-Camel query name prefi…

Read more
Apache Camel CVE-2026-48205 SSRF Vulnerability Advisory
camel.apache.org · 2026-07-06

### Vulnerability Overview - **Vulnerability Name**: CVE-2026-48205 - **Severity**: Medium - **Description**: The `dns.*` and `term` Exchange header constants in Apache Camel used non-Camel prefixed n…

Read more
Apache Camel WebSocket SSRF via Unfiltered Headers (CVE-2026-46726)
camel.apache.org · 2026-07-06

### Vulnerability Overview - **Vulnerability Name**: CVE-2026-46726 - **Severity**: High - **Description**: The Apache Camel WebSocket consumer maps externally provided WebSocket query and path parame…

Read more
Apache Camel Iguana Consumer SSRF Vulnerability Analysis (CVE-2026-55994)
camel.apache.org · 2026-07-06

### Vulnerability Overview **Vulnerability Name**: CVE-2026-55994 **Severity**: High **Description**: The Iguana consumer in Apache Camel maps externally provided Iguana message user headers into the …

Read more
Apache Camel CVE-2026-55993 WebSocket SSRF and Header Injection
camel.apache.org · 2026-07-06

### Vulnerability Overview - **Vulnerability Name**: CVE-2026-55993 - **Severity**: High - **Description**: The Apache Camel-Atmosphere-WebSocket component fails to apply the HeaderFilterStrategy when…

Read more
CVSS 5.0
Rancher Fleet SSRF Vulnerability in Helm Repo Auth (CVE-2026-44936)
github.com · 2026-07-06

### Vulnerability Overview Rancher Fleet has an SSRF (Server-Side Request Forgery) vulnerability in the Bundle Reader within `fleet.yaml` due to unvalidated Helm repository URLs. When the `helmRepoURL…

Read more
Swoosh MsGraph Adapter Email-Derived URL Injection Leads to SSRF (CVE-2026-54893)
cna.erlef.org · 2026-07-06

### Vulnerability Overview - **CVE ID**: CVE-2026-54893 - **Vulnerability Name**: Email-derived URL path injection in the Swoosh Microsoft Graph adapter - **Weakness Type (CWE)**: CWE-116 — CWE-116 Im…

Read more
Premium intel
CVSS 8.5
ownCloud SharePoint SSRF Vulnerability CVE-2025-53629 and Security Patch
github.com · 2026-07-07

### Vulnerability Overview - **Vulnerability Name**: [OC10] SharePoint for ownCloud 10 before 0.4.1 is vulnerable to Server-Side Request Forgery (SSRF) - **Risk Level**: High - **CVSS v3 Base Score**:…

Read more
CVSS 8.6
Unauthenticated SSRF Vulnerability in Docker Server Crawl Stream Path
github.com · 2026-07-07

# Unauthenticated SSRF Vulnerability in Docker Server's Streaming Crawl Path (`/crawl/stream`) ## Vulnerability Overview The Docker API server applies an SSRF destination check (`validate_url_destinat…

Read more
Premium intel
CVSS 8.8
coollabsio/cooliing v4.0.0-beta.474 Security Patch: Shell Injection, SSRF, and Webhook Key Remediation
github.com · 2026-07-07

### Vulnerability Overview In the `coollabsio/cooliing` project, multiple security-related issues exist that could potentially lead to data loss, service disruption, or security vulnerabilities. ### I…

Read more
Premium intel
CVSS 8.1
mcp-gateway-registry v1.0.13: SSRF (CVE-918), SQLi, Info Disclosure Fix
github.com · 2026-07-07

### Vulnerability Overview In version `v1.0.13`, the following security-related issues have been resolved: 1. **SSRF Protection**: SSRF protection was added to redirect validation (CVE-918). 2. **SQL …

Read more
Premium intel
CVSS 10.0
unclecode/crawl4ai Docker hardening and fix for SSRF/Redis path traversal
github.com · 2026-07-07

### Vulnerability Overview The webpage screenshot displays the commit history for the project `unclecode/crawl4ai`, primarily focusing on Docker server hardening and the release of security patches. S…

Read more
CVSS 4.9
SSRF Fix: Strengthening S3 Storage Endpoint Validation in SafeWebhookUrl
github.com · 2026-07-07

### Vulnerability Overview This vulnerability concerns the strengthening of validation for S3 storage endpoint URLs. Specifically, the flaw exists within the `SafeWebhookUrl` rule, which is used to va…

Read more
CVSS 4.9
Coolify SSRF via S3 Storage Endpoint in testConnection()
github.com · 2026-07-07

### Vulnerability Overview **Vulnerability Name**: SSRF via S3 Storage Endpoint in testConnection() **Vulnerability Type**: CWE-918 - Server-Side Request Forgery (SSRF) **Description**: The Coolify S3…

Read more
CVSS 4.3
Coolify SSRF in GitHub App API URL via Livewire UI (GHSA-3gfr-cxv5-3c7h)
github.com · 2026-07-07

### Vulnerability Overview **Vulnerability Name**: Server-Side Request Forgery via Attacker-Controlled GitHub App API URL **Vulnerability ID**: GHSA-3gfr-cxv5-3c7h **Severity**: Medium (CVSS 3.1: 5.0)…

Read more
CVSS 5.5
NocoBase SSRF Vulnerability: Unrestricted Outbound HTTP Requests in Default Deployment
github.com · 2026-07-08

### Vulnerability Overview - **Vulnerability Name**: SSRF - Outbound HTTP requests are unrestricted in default NocoBase deployments - **Vulnerability ID**: #9962 - **Reporter**: geo-chen - **Report Da…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.