Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 599— Search: SSRF×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 8.6
Swarms SSRF bypass in remote image fetch and OAuth token cache leak
github.com · 2026-07-30

### Vulnerability Overview - **Vulnerability Name**: SSRF bypass in remote image fetch and world-readable OAuth token cache - **Vulnerability ID**: #1734 - **Vulnerability Type**: SSRF (Server-Side Re…

Read more
Premium intel
CVSS 8.6
SSRF bypass in swarmutils image/audio loaders via DNS rebinding
github.com · 2026-07-30

### Vulnerability Overview - **Vulnerability Name**: SSRF via incomplete URL filter in image/audio loaders (hostname resolving to internal IP bypasses the guard) #1714 - **Vulnerability Type**: SSRF (…

Read more
Premium intel
CVSS 8.6
SSRF and File Permission Vulnerability Fix Details
github.com · 2026-07-30

### Vulnerability Overview The screenshot of the webpage displays a commit identified as `8b0fc9e`, which involves multiple security-related fixes and improvements. The primary vulnerabilities include…

Read more
CVSS 4.3
GitLab Shell Injection/SSRF/DoS/ACL Bypass Vulnerabilities and Fixes Analysis
github.com · 2026-07-30

### Vulnerability Overview The provided webpage screenshot illustrates a discussion and remediation process regarding security vulnerabilities. The primary vulnerabilities involved are: 1. **Shell Aft…

Read more
Premium intel
CVSS 8.5
flyto-core SSRF via HTTP Redirect Bypass (CVE-2026-67424)
github.com · 2026-07-30

### Vulnerability Overview **Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation** This vulnerability affects the HTTP modules within the `flyto-core` package (…

Read more
Premium intel
CVSS 10.0
HashiCorp Terraform MCP Server Vulnerabilities: SSRF, Auth Bypass, Credential Reuse (CVE-2026-14869/16496/16498)
discuss.hashicorp.com · 2026-07-30

### Vulnerability Overview **HCSEC-2026-23 - Multiple Vulnerabilities Affecting HashiCorp Terraform MCP Server** - **Vulnerability ID**: HCSEC-2026-23 - **Publication Date**: July 28, 2026 - **Affecte…

Read more
CVSS 7.5
datamodel-code-generator SSRF Bypass via DNS Rebinding (CVE-2025-55391)
github.com · 2026-07-29

### Vulnerability Overview **Vulnerability Name**: SSRF protection bypass via DNS rebinding **CVE ID**: CVE-2025-55391 **CVSS v3.1 Score**: 7.5/10 **Severity**: High **Description**: The SSRF protecti…

Read more
CVSS 7.7
PhpSpreadsheet SSRF Bypass via HTTP Redirect in WEBSERVICE Function
github.com · 2026-07-29

### Vulnerability Overview **Vulnerability Name**: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist **Description**: The domain whitelist for the `WEBSERVICE()` formula function, introdu…

Read more
Premium intel
CVSS 7.2
Cross-origin OAuth redirect info leak & SSRF in Ruby oauth lib (CVE-2026-54005)
github.com · 2026-07-29

### Vulnerability Overview **Title**: Cross-origin OAuth token-request redirects can expose signed request metadata **Description**: When an application uses `OAuth::Consumer` to request an OAuth 1.0 …

Read more
CVSS 8.3
Next.js v15.5.21 Security Update: SSRF, Middleware Bypass & DoS Vulnerabilities
github.com · 2026-07-28

### Vulnerability Overview - **Version**: v15.5.21 - **Release Date**: Last week - **Author**: eps1lon ### Impact Scope #### High-Severity Vulnerabilities 1. **Denial of Service in App Router** - Desc…

Read more
Premium intel
CVSS 8.3
Next.js v16.2.11 Security Advisory: SSRF, Middleware Bypass, and DoS Fixes
github.com · 2026-07-28

### Vulnerability Overview - **Version**: v16.2.11 - **Release Date**: Last week - **Release Author**: eps1lon - **Security Fixes**: Includes fixes for the following security vulnerabilities ### Impac…

Read more
CVSS 3.5
SSRF bypass in Papra webhook delivery (Pre-Auth) with POC and patch
github.com · 2026-07-28

### Vulnerability Overview **Vulnerability Name**: SSRF via HTTP redirect bypass in webhook delivery **Vulnerability Description**: The Papra webhook delivery system contains an SSRF protection bypass…

Read more
CVSS 5.5
FetchURL SSRF Bypass via DNS Rebinding and Redirects Vulnerability Analysis
github.com · 2026-07-27

### Vulnerability Overview This vulnerability involves SSRF (Server-Side Request Forgery) bypasses and DNS rebinding issues in the `FetchURL` tool. The `FetchURL` tool originally relied on a static ho…

Read more
Printcart Web to Print for WooCommerce <2.5.3 Unauthenticated Arbitrary File Read and SSRF (CVE-2025-15662)
wpscan.com · 2026-07-27

# Printcart Web to Print Product Designer for WooCommerce root:x:0:0:... # Use url=file:///var/www/html/wp-config.php to retrieve DB credentials and auth salts. # 3) Server-Side Request Forgery target…

Read more
CVSS 6.3
openlaw-cn SSRF bypass to loopback/private targets via /act interaction
github.com · 2026-07-26

### Vulnerability Overview **Title**: Browser interaction-driven navigation bypasses `browser.ssrPolicy` and reaches loopback/private targets #562 **Description**: In `openlaw-cn`, the authenticated b…

Read more
CVSS 4.1
Shopware SSRF in Media Endpoint Bypasses IP Validation
github.com · 2026-07-24

### Vulnerability Overview **Vulnerability Name**: SSRF in Media External-Link Endpoint Bypasses IP Validation **Description**: In Shopware’s `/api/action/media/external-link` endpoint, authenticated …

Read more
LLM CTF Challenge Bypass: SSRF and Non-Expected Path Analysis in Qwen3, Grok, DeepSeek
projectdiscovery.io · 2026-07-22

### Vulnerability Overview - **Vulnerability Name**: Not explicitly named; involves multiple case studies. - **Vulnerability Description**: - **Qwen3.6-27B**: When attempting to solve challenges, the …

Read more
CVSS 7.1
CC-Tweaked SSRF Bypass via NAT64 Prefix: Vulnerability, POC, and Fix
github.com · 2026-07-22

# SSRF Protection Bypass with NAT64 ## Vulnerability Overview The HTTP API (`http.request`, `http.request`, `http.websocket`) in CC-Tweaked is designed to block requests to private network ranges to p…

Read more
CVSS 8.2
SSRF Vulnerability in visit_page Tool via Cloud Metadata Access
github.com · 2026-07-22

### Vulnerability Overview **Vulnerability Name**: SSRF via `visit_page` **Vulnerability Type**: Server-Side Request Forgery (SSRF) **Vulnerability Description**: The `visit_page` utility loads a user…

Read more
Premium intel
CVSS 8.6
Unauthenticated SSRF and CORS Bypass in Verba RAG Application
github.com · 2026-07-22

### Vulnerability Overview #### Vulnerability 1: Unauthenticated SSRF in Verba WebSocket Import Endpoint (HTMLReader) - **Details**: An unauthenticated Server-Side Request Forgery (SSRF) vulnerability…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.