agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed

through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user

CVSS 7.1 Langflow OSS View details

plus a caller-supplied path and returns the full response body. MLflow's existing SSRF guard, _validate_webhook_url (which blocks non-global and metada

CVE MEDIUM CVE-2026-70480

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

CVSS 4.1 open-webui View details
CVE UNKNOWN CVE-2026-69250

Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration

CVE CRITICAL CVE-2026-67429

Flyto2 Core: Arbitrary file write via image.download (and other file

CVSS 10.0 flyto-core View details

attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version

CVSS 8.6 flyto-core View details
CVE MEDIUM CVE-2026-65593

restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private

CVSS 8.6 lmdeploy View details

text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server

CVSS 8.6 text-generation-inference View details

them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services

CVSS 8.5 PraisonAI View details

server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve

CVSS 8.5 praisonai View details

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from

time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack

CVSS 7.2 praisonai View details

vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers

CVSS 7.4 gradio View details
CVE CRITICAL CVE-2026-59706

attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network

CVE MEDIUM CVE-2026-9557

Mautic Focus component Vulnerable to SSRF

CVSS 6.4 mautic/core View details
CVE MEDIUM CVE-2026-56399

side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services

CVSS 5.0 open-webui View details
CVE MEDIUM CVE-2026-10546

Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that

CVSS 6.5 langflow View details
Previous Page 4 of 9 Next