OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation

OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths

OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection

CVE MEDIUM CVE-2022-36551

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

CVSS 6.5 label-studio View details
CVE MEDIUM CVE-2026-70480

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

CVSS 4.1 open-webui View details
CVE MEDIUM CVE-2026-65593

restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled

CVE MEDIUM CVE-2026-9557

Mautic Focus component Vulnerable to SSRF

CVSS 6.4 mautic/core View details
CVE MEDIUM CVE-2026-56399

side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services

CVSS 5.0 open-webui View details
CVE MEDIUM CVE-2026-10546

Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that

CVSS 6.5 langflow View details
CVE MEDIUM CVE-2026-54033

setting a baseURL. This URL is used to construct HTTP requests without any SSRF validation — no private IP check, no scheme restriction, no DNS pinning. An authenticated user

CVE MEDIUM CVE-2026-49345

mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery (SSRF) vulnerability exists in Mercator's CVE configuration panel (`/admin/config/parameters`). The `testProvider()` method in `ConfigurationController` passes

CVE MEDIUM CVE-2026-3341

Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading

CVSS 5.4 langflow View details
CVE MEDIUM CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

CVSS 5.5 PraisonAI View details
CVE MEDIUM CVE-2026-3340

Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading

CVSS 6.5 langflow View details
CVE MEDIUM CVE-2026-41481

attacker-controlled server could redirect to internal, localhost, or cloud metadata endpoints, bypassing SSRF protections. The resp

CVSS 6.5 langchain View details

OpenClaw: Browser snapshot and screenshot routes could expose internal page

Flowise Execute Flow function has an SSRF vulnerability

flowise-components View details
Previous Page 2 of 4 Next