Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 615— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 4.7
SSRF in GoCLAW TTS API via Unvalidated URL Config (PoC)
github.com · 2026-06-02

### Vulnerability Overview **Title**: Server-Side Request Forgery (SSRF) via Unvalidated TTS Provider API Base Configuration #1132 **Description**: An unvalidated URL field exists in the Text-to-Speec…

Read more
Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8 · Advisory · gotenberg/gotenberg · GitHub
github.com · 2026-05-22

# Server-Side Request Forgery (SSRF) Vulnerability Summary **Vulnerability Name**: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8 **Reporter**: gullien **Published**: 3 weeks …

Read more
CVSS 7.3
NextChat SSRF via Unvalidated x-base-url Header (Open Proxy Fallback)
github.com · 2026-04-28

# [Security] Server-Side Request Forgery (SSRF) via Open Proxy Fallback (x-base-url Header) #6742 ## Vulnerability Overview NextChat has a Server-Side Request Forgery (SSRF) vulnerability. When the re…

Read more
Premium intel
CVSS 7.3
SSRF vulnerability in adafap/api-mcp POST /api/proxy with PoC
github.com · 2026-08-10

### Vulnerability Overview **Vulnerability Name**: SSRF via `/api/proxy` URL in adafap/api-mcp #4 **Vulnerability Type**: Server-Side Request Forgery (SSRF) **Vulnerability Description**: - The `POST …

Read more
Premium intel
CVSS 7.7
SSRF Vulnerability Fix Analysis and PoC Code in UploadService
github.com · 2026-06-13

### Vulnerability Overview This vulnerability is a Server-Side Request Forgery (SSRF) flaw located in the `uploadFromUrl` function. An attacker can craft malicious URLs to induce the server to make un…

Read more
CVSS 7.7
openclaw CDP WebSocket SSRF Vulnerability Fix
github.com · 2026-05-07

### Vulnerability Overview This vulnerability involves hardening the direct CDP (Chrome DevTools Protocol) WebSocket validation in the `openclaw` project. The specific issue is that the CDP WebSocket …

Read more
WGDashboard SSRF Vulnerability Analysis and PoC via Webhooks
github.com · 2026-08-07

### WGDashboard Full-Read SSRF via Webhooks PoC | WGDashboard #### Vulnerability Overview - **Vulnerability Type**: Server-Side Request Forgery (SSRF) - **Description**: The webhook functionality in W…

Read more
CVSS 7.5
SSRF via $ref Dereferencing in mcp-from-openapi
github.com · 2026-04-09

### Vulnerability Summary: SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications **Vulnerability Overview** This vulnerability exists in the `mcp-from-openapi` library. When the `OpenAPITool…

Read more
SSRF Vulnerability in SillyTavern CORS Proxy Middleware (CVE-2024-4652)
github.com · 2026-05-30

### Vulnerability Overview **Vulnerability Name**: SSRF vulnerability in the CORS proxy middleware **CVE ID**: CVE-2024-4652 **Severity**: Moderate **Publication Status**: Published **Description**: S…

Read more
CVSS 7.7
Fix SSRF & Credential Leakage in fourclement Poll.at status polling
github.com · 2026-04-04

### Key Vulnerability Information Summary **Vulnerability Overview** * **Type**: SSRF (Server-Side Request Forgery) and Credential Leakage. * **Description**: A vulnerability in the `fourclement` modu…

Read more
SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL() · Advisory · WWBN/AVideo · GitHub
github.com · 2026-05-22

# SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFsSafeURL() ## Vulnerability Overview This vulnerability involves two security issues in the `isSSRFsSafeURL()` function of the `WW…

Read more
Premium intel
CVSS 8.6
Unauthenticated SSRF in January /proxy and /embed Endpoints
github.com · 2026-07-16

### Vulnerability Overview **Vulnerability Name**: Unauthenticated SSRF in January Proxy and Embed Endpoints **CVE ID**: No known CVE **CVSS v3 Base Metrics**: - Attack Vector: Network - Attack Comple…

Read more
CVSS 7.3
NextChat SSRF Vulnerability Leads to Cloudflare API Token Leakage
github.com · 2026-04-28

# Vulnerability Summary: Server-Side Request Forgery (SSRF) and Cloudflare API Token Leakage ## Vulnerability Overview - **Vulnerability Type**: Server-Side Request Forgery (SSRF) and Cloudflare API T…

Read more
CVSS 7.3
NextChat SSRF and Cloudflare API Token Leakage via Path Traversal
gist.github.com · 2026-04-28

### Vulnerability Overview **Title**: Server-Side Request Forgery (SSRF) and Cloudflare API Token Leakage via Path Traversal in Artifacts Endpoint **Description**: - **Vulnerability Type**: SSRF and C…

Read more
CVSS 5.0
SilkyWann <1.16.0 SSRF via Incomplete IP Validation (CVE-2025-2626)
github.com · 2026-04-03

# Vulnerability Summary: Incomplete IP Validation in `/api/search/visit` Allows

Read more
CVSS 5.8
DoraCMS 3.1 UEditor SSRF Vulnerability Analysis Report
github.com · 2026-02-11

## DoraCMS 3.1 Security Report SSRF (Responsible Disclosure) ### Report Title SSRF via UEditor Remote Image Fetch (catcher/catchImage) ### Product DoraCMS 3.1 ### Date 2026-02-10 ### Scope Source-code…

Read more
Release v0.9.5 · open-webui/open-webui · GitHub
github.com · 2026-05-22

# Vulnerability Summary ## Overview - **Redirect-based SSRF protection**: Introduced the `ALLOW_REDIRECTS` environment variable to block 3xx redirects in outbound HTTP requests, preventing SSRF attack…

Read more
CVSS 6.7
compliance-trestle SSRF and Path Traversal Vulnerability (CVE-2025-45380) Advisory
github.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: Critical SSRF (CWE-918) - **Vulnerability Description**: Three significant security vulnerabilities were identified in the `compliance-trestle` `co…

Read more
Apache Batik/FOP/XML Graphics Commons SSRF/XXE/Deserialization Vulnerabilities Summary (CVE-2022-44729 etc.)
xmlgraphics.apache.org · 2024-10-10

From this webpage screenshot, the following key information about vulnerabilities can be obtained: 1. **Apache Batik Project - Apache Batik Security**: - Batik 1.17: SSRF vulnerability CVE-2022-44729 …

Read more
CVSS 6.3
Second-Order SSRF in JeecgBoot Announcement Download
github.com · 2026-05-02

# [Security] Second-Order SSRF in jeecgboot_JeecgBoot #9553 ## Vulnerability Overview A second-order Server-Side Request Forgery (SSRF) vulnerability exists in the announcement file download functiona…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.