Skip to main content

About CWE-918

Requests appear to come from the server, so they may pass firewalls and reach internal hosts. The server can be used to scan internal hosts, read local documents through file URLs, or speak other protocols that give more control over request contents.

MITRE name
Server-Side Request Forgery (SSRF)
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Incomplete
Also known as
XSPA, SSRF

Mitigations

  • When the set of destinations is known, validate requests against an allowlist of permitted applications, addresses or domains (OWASP).
  • Disable automatic following of redirects in the HTTP client so validation cannot be bypassed (OWASP).
  • Restrict the application's outbound network routes with firewall rules and network segregation (OWASP).
  • In AWS, migrate to IMDSv2 and disable IMDSv1 as defense in depth for metadata access (OWASP).

Detection
Automated static analysis (SAST) is rated highly effective by MITRE for this weakness.

CWE-918 Vulnerabilities

8 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-83548
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall10.08.8%KEV2026-09-01
CVE-2026-49869
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
kestra-io10.02.1%KEV2026-06-26
CVE-2026-64849
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow9.39.8%KEV2026-08-17
CVE-2026-15409
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall10.06.8%KEV2026-07-14
CVE-2021-21311
SSRF in adminer
vrana7.298.5%KEV2021-02-11
CVE-2023-41763
Skype for Business Elevation of Privilege Vulnerability
Microsoft5.390.4%KEV2023-10-10
CVE-2021-40438
mod_proxy SSRF
Apache Software Foundation9.0100.0%KEV2021-09-16
CVE-2026-22219
Chainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element
Chainlit8.35.1%2026-01-19

Frequently Asked Questions

What is CWE-918?→

CWE-918 is server-side request forgery. A server fetches a URL supplied from outside without confirming the destination is one it should contact.

Are denylists of internal IP ranges enough to stop SSRF?→

OWASP calls deny-lists bypass-prone and a last resort. It recommends allowlists plus network-level restrictions.

How many exploited vulnerabilities are classified as CWE-918?→

This database lists 8 CVE records mapped to CWE-918 by their CVE Numbering Authority. 7 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-83548, CVE-2026-49869, CVE-2026-64849.

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.