CVE CRITICAL CVE-2026-25960

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from

CVSS 9.8 vllm View details

powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

CVSS 8.5 open-webui View details
CVE MEDIUM CVE-2025-12058

mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from

source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet

CVSS 8.6 lobe_chat View details

SSRF Protection Bypass via MCP Client Node

CVE MEDIUM CVE-2026-55414

Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF

CVSS 5.3 nl.nl-portal:form View details

IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders

CVSS 8.5 n8n-mcp View details

OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook

CVSS 7.2 PraisonAI View details

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation

OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths

OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection

OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete

CVSS 7.4 openclaw View details
CVE CRITICAL CVE-2025-54381

model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests

CVSS 9.9 bentoml View details
CVE CRITICAL CVE-2024-47167

Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function allows attackers

CVSS 9.8 gradio View details
CVE MEDIUM CVE-2022-36551

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

CVSS 6.5 label-studio View details
Previous Page 3 of 9 Next