vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from
powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from
source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet
Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF
IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook
OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection
OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete
model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests
Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function allows attackers
Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module