Server-Side Request Forgery (CWE-918)
CWE-918 applies when a web server takes a URL or similar request from an upstream component and fetches it without making sure the request goes to the expected destination. The server then acts as a proxy for the caller. MITRE notes a close relation to XXE (CWE-611), which can also trigger outbound requests.
About CWE-918
Requests appear to come from the server, so they may pass firewalls and reach internal hosts. The server can be used to scan internal hosts, read local documents through file URLs, or speak other protocols that give more control over request contents.
Mitigations
- When the set of destinations is known, validate requests against an allowlist of permitted applications, addresses or domains (OWASP).
- Disable automatic following of redirects in the HTTP client so validation cannot be bypassed (OWASP).
- Restrict the application's outbound network routes with firewall rules and network segregation (OWASP).
- In AWS, migrate to IMDSv2 and disable IMDSv1 as defense in depth for metadata access (OWASP).
Detection
Automated static analysis (SAST) is rated highly effective by MITRE for this weakness.
CWE-918 Vulnerabilities
8 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall | 10.0 | 8.8% | KEV | 2026-09-01 |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` | kestra-io | 10.0 | 2.1% | KEV | 2026-06-26 |
| CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | mlflow | 9.3 | 9.8% | KEV | 2026-08-17 |
| CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall | 10.0 | 6.8% | KEV | 2026-07-14 |
| CVE-2021-21311 | SSRF in adminer | vrana | 7.2 | 98.5% | KEV | 2021-02-11 |
| CVE-2023-41763 | Skype for Business Elevation of Privilege Vulnerability | Microsoft | 5.3 | 90.4% | KEV | 2023-10-10 |
| CVE-2021-40438 | mod_proxy SSRF | Apache Software Foundation | 9.0 | 100.0% | KEV | 2021-09-16 |
| CVE-2026-22219 | Chainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element | Chainlit | 8.3 | 5.1% | 2026-01-19 |
Frequently Asked Questions
What is CWE-918?→
CWE-918 is server-side request forgery. A server fetches a URL supplied from outside without confirming the destination is one it should contact.
Are denylists of internal IP ranges enough to stop SSRF?→
OWASP calls deny-lists bypass-prone and a last resort. It recommends allowlists plus network-level restrictions.
How many exploited vulnerabilities are classified as CWE-918?→
This database lists 8 CVE records mapped to CWE-918 by their CVE Numbering Authority. 7 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-83548, CVE-2026-49869, CVE-2026-64849.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.