Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 606— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 7.7
Open WebUI v0.8.11 Security Patch Summary: SSRF, Bypass, Session Fixation
github.com · 2026-04-02

# Open WebUI v0.8.11 Security Vulnerability Fixes Summary ## Vulnerability Overview This release fixes multiple security vulnerabilities, primarily involving **model access control bypass**, **termina…

Read more
CVSS 7.3
ImEditor SSRF Vulnerability Analysis (CVSS 7.5) with POC
github.com · 2026-04-03

# ImEditor 服务端请求伪造 (SSRF) 漏洞总结 ### 漏洞概述 * **漏洞名称:** Server-Side Request Forgery (SSRF) Vulnerability in ImEditor #11 * **CVSS 评分:** 7.5 (High) * **描述:** ImEditor 的 `upload.php` 脚本存在服务端请求伪造漏洞。攻击者可通过构造恶…

Read more
Premium intel
CVSS 6.1
Roundcube Webmail Security Update: SSRF, XSS, Deserialization Fixes
roundcube.net · 2026-04-03

### 漏洞概述 Roundcube Webmail 发布安全更新(版本 1.7-rc5、1.6.14 和 1.5.14),修复了多个近期报告的安全漏洞。 ### 影响范围 - Roundcube Webmail 1.6 和 1.5 LTS 版本 - Roundcube Webmail 1.7 的候选版本(1.7-rc5) ### 修复方案 建议立即升级至以下版本以修复所有已知漏洞: - **1.…

Read more
CVSS 6.3
SSRF Vulnerability in google-search-api Library (CVSS 8.8)
github.com · 2026-04-04

This request asks me to summarize a webpage screenshot regarding a "Google Search Server-Side Request Forgery (SSRF) Vulnerability." **1. Vulnerability Overview:** * **Title:** Server-Side Request For…

Read more
CVSS 7.3
Unauthenticated SSRF in GPT Researcher WebSocket (CVSS 9.1) with POC
github.com · 2026-04-06

### Vulnerability Overview * **Vulnerability Name**: Unauthenticated WebSocket Source URL SSRF Vulnerability (Unauthenticated SSRF via WebSocket source_urls) * **Affected Product**: GPT Researcher * *…

Read more
CVSS 8.3
OpenHarness Path Traversal and SSRF Vulnerability Fix Analysis
github.com · 2026-04-18

# Vulnerability Summary ## Vulnerability Overview This commit fixes vulnerabilities related to Path Traversal and Web Guards in the OpenHarness project. The main issue lies in insufficient permission …

Read more
CVSS 8.6
Chamilo PensProcessor SSRF Fix: Strict Private IP Validation
github.com · 2026-04-18

# Vulnerability Summary ## Overview This vulnerability involves **insufficiently strict URL validation logic**, which may allow access to private/reserved address ranges (such as internal network addr…

Read more
ProcessWire CMS Admin SSRF Vulnerability Analysis
gist.github.com · 2026-04-18

# ProcessWire CMS SSRF Vulnerability Summary ## Vulnerability Overview A **Server-Side Request Forgery (SSRF)** vulnerability exists in the admin panel of ProcessWire CMS (v3.0.255). The flaw is locat…

Read more
CVSS 4.3
CVE-2026-41687: SSRF CGNAT Bypass in wallios via is_cgnat_ip() Omission
github.com · 2026-05-07

# SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks (CWE-918) ## Vulnerability Overview - **Vulnerability Type**: CWE-918 Server-Side Request Forgery (SSRF)…

Read more
CVSS 8.5
n8n-mcp SSRF bypass via IPv4-mapped IPv6 addresses (CVE-2025-42449)
github.com · 2026-05-08

# Vulnerability Summary: IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync() ## Vulnerability Overview - **Vulnerability Name**: IPv4-mapped IPv6 addresses bypass SSRF protection in…

Read more
CVSS 5.4
WordPress nexus-blocks 1.1.1 SSRF via unvalidated URL import
plugins.trac.wordpress.org · 2026-05-22

### Vulnerability Overview The screenshot shows a code file from the WordPress plugin directory, specifically `nexus-blocks/tags/1.1.1/inc/template/template.php`. The file contains a potential securit…

Read more
CVSS 4.3
WordPress EditorCanvas Plugin Privilege Escalation & SSRF Mitigation Analysis
plugins.trac.wordpress.org · 2026-05-22

### Vulnerability Overview The screenshot shows a code file within a WordPress plugin directory, specifically `EditorCanvas.php`. The file contains a potential security vulnerability related to the pr…

Read more
Premium intel
CVSS 8.1
Roundcube Webmail Security Update: Fixes XSS, SQLi, SSRF, and RCE
roundcube.net · 2026-05-26

# Roundcube Webmail Security Update Summary (v1.6.16 & v1.7.1) ## Vulnerability Overview This update addresses multiple recently reported security vulnerabilities in Roundcube Webmail, primarily invol…

Read more
CVSS 7.2
Roundcube SSRF Local Address Bypass: Analysis and Patch Details
github.com · 2026-05-26

### Vulnerability Overview This vulnerability involves bypassing SSRF (Server-Side Request Forgery) restrictions through specific local address URLs. SSRF is an attack where an attacker can exploit a …

Read more
CVSS 7.6
Karkeep SSRF Redirect Bypass Vulnerability via HTTP Chain
github.com · 2026-05-26

### Vulnerability Overview A Server-Side Request Forgery (SSRF) protection bypass vulnerability has been discovered in Karkeep, affecting the redirect handling component. Although the application impl…

Read more
CVSS 4.3
PHP SSRF Bypass: IPv4-mapped IPv6 URL Validation Bypass and Fix
github.com · 2026-05-27

### Vulnerability Overview This vulnerability involves an issue with IPv4-mapped IPv6 addresses in SSRF (Server-Side Request Forgery) scope checks. Specifically, the `testIsSafeUrl()` function rejects…

Read more
CVSS 7.7
Budibase SSRF Vulnerability: Plugin URL Upload .tar.gz Substring Bypass and Blacklist Bypass
github.com · 2026-05-28

### Vulnerability Overview **Title**: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`) **Product**: Budibase (Self-Hosted) **Version**: ≤ 3.34.11 (as of 2026-03-30) **C…

Read more
CVSS 6.5
WordPress plugin independent-analytics SSRF/RCE vulnerability analysis
plugins.trac.wordpress.org · 2026-05-28

### Vulnerability Overview The provided screenshot displays a file named `FaviconDownloader.php`, which is part of the WordPress plugin `independent-analytics`. The file contains a potential security …

Read more
Premium intel
CVSS 8.5
Security Advisory v2.4.33: Fixes SSRF, Permission Bypass, and CVE-2026-44243/44244
github.com · 2026-05-29

### Vulnerability Overview Multiple security vulnerabilities were identified in version `v2.4.33`, affecting Webhook configuration, API permission controls, and regular expression processing. ### Scop…

Read more
CVSS 5.0
GHSA-g23j-2vwm-5c29: SSRF Parser Differential Bypass and IPv6 Unspecified Address Mitigation
github.com · 2026-05-29

### Vulnerability Overview This vulnerability pertains to the hardening of SSRF (Server-Side Request Forgery) protections, specifically covering: - **SSRF Parser Differential Bypass**: Bypassing SSRF …

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.