Threadlinqs IntelligenceStart free

Weakness · BaseCWE-918

CWE-918: Server-Side Request Forgery (SSRF)

KEV-linkedBase

As of 2026-10-05, CWE-918 (SSRF) underlies 76 CVEs tracked by Threadlinqs, 10 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 85 tracked threats.

CVEs
76Mapped to CWE-918
CISA KEV
10Exploited in the wild
Critical
11CVSS v3 critical CVEs
Threats
85Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-918?

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

CWE-918 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: AI/ML; Technology: Web Server.

Source: MITRE CWE (CWE-918 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality — Read Application Data
  • Integrity — Execute Unauthorized Code or Commands
  • Access Control — Bypass Protection Mechanism. By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the…

Source: MITRE CWE, common consequences.

How CWE-918 is exploited in the wild

Threadlinqs maps 76 CVEs to CWE-918, published between 2021-03-03 and 2026-10-03. 10 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 4 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 11 critical, 28 high, 27 medium, 3 low. The highest EPSS score in the set is 97.5% (CVE-2025-61884), the modelled probability of exploitation in the next 30 days. 85 tracked threats reference CWE-918 directly or through a CVE it covers; the most recent is “AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019” (2026-10-03). Affected products concentrate in Microsoft (7), IBM (3), jfrog (3), among 58 vendors in total.

Vulnerabilities (CVEs)

Showing 40 of 76 CVEs mapped to CWE-918, CISA KEV first, then by CVSS score.

  • CVE-2026-83548 — CISA KEV · CVSS 10 critical · EPSS 0.2% · published 2026-09-01
  • CVE-2026-15409 — CISA KEV · CVSS 10 critical · published 2026-07-14
  • CVE-2021-34473 — CISA KEV · CVSS 9.1 critical · EPSS 94.1% · published 2021-07-14
  • CVE-2021-26855 — CISA KEV · CVSS 9.1 critical · EPSS 93.9% · published 2021-03-03
  • CVE-2022-41040 — CISA KEV · CVSS 8.8 high · EPSS 94.1% · published 2022-10-03
  • CVE-2026-20230 — CISA KEV · CVSS 8.6 high · EPSS 41.6% · published 2026-06-03
  • CVE-2024-21893 — CISA KEV · CVSS 8.2 high · EPSS 94.3% · published 2024-01-31
  • CVE-2025-61884 — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
  • CVE-2021-22054 — CISA KEV · CVSS 7.5 high · EPSS 93.8% · published 2021-12-17
  • CVE-2021-39935 — CISA KEV · CVSS 6.8 medium · EPSS 41.4% · published 2021-12-13
  • CVE-2026-48331 — CVSS 10 critical · published 2026-08-03
  • CVE-2026-45499 — CVSS 9.9 critical · EPSS 0.6% · published 2026-07-02
  • CVE-2026-57100 — CVSS 9.9 critical · published 2026-07-02
  • CVE-2023-48022 — CVSS 9.8 critical · EPSS 83.9% · published 2023-11-28
  • CVE-2026-22874 — CVSS 9.6 critical · EPSS 0.4% · published 2026-07-03
  • CVE-2026-75332 — CVSS 9.1 critical · EPSS 0.1% · published 2026-08-26
  • CVE-2026-75340 — CVSS 9.1 critical · EPSS 0.1% · published 2026-08-26
  • CVE-2026-5921 — CVSS 8.9 high · EPSS 0.0% · published 2026-04-21
  • CVE-2026-82097 — CVSS 8.8 high · EPSS 0.3% · published 2026-09-10
  • CVE-2026-72848 — CVSS 8.6 high · EPSS 0.4% · published 2026-08-20
  • CVE-2026-62242 — CVSS 8.6 high · EPSS 0.2% · published 2026-07-13
  • CVE-2026-73247 — CVSS 8.6 high · published 2026-08-11
  • CVE-2026-72860 — CVSS 8.5 high · EPSS 0.2% · published 2026-08-20
  • CVE-2026-62197 — CVSS 8.5 high · EPSS 0.2% · published 2026-07-13
  • CVE-2026-77348 — CVSS 8.2 high · EPSS 0.2% · published 2026-08-31
  • CVE-2026-9312 — CVSS 8.2 high · EPSS 0.0% · published 2026-05-27
  • CVE-2026-69855 — CVSS 7.7 high · EPSS 0.4% · published 2026-08-20
  • CVE-2026-33626 — CVSS 7.5 high · EPSS 2.9% · published 2026-04-20
  • CVE-2026-85917 — CVSS 7.5 high · EPSS 0.5% · published 2026-09-17
  • CVE-2026-55391 — CVSS 7.5 high · published 2026-07-28
  • CVE-2026-62240 — CVSS 7.4 high · EPSS 0.2% · published 2026-07-13
  • CVE-2026-9006 — CVSS 7.4 high · EPSS 0.2% · published 2026-06-22
  • CVE-2026-82957 — CVSS 7.3 high · EPSS 0.3% · published 2026-08-31
  • CVE-2026-19374 — CVSS 7.3 high · EPSS 0.3% · published 2026-08-09
  • CVE-2026-19753 — CVSS 7.3 high · EPSS 0.2% · published 2026-08-13
  • CVE-2026-86539 — CVSS 7.2 high · EPSS 0.2% · published 2026-09-07
  • CVE-2026-61953 — CVSS 7.2 high · EPSS 0.1% · published 2026-07-27
  • CVE-2026-65442 — CVSS 7.2 high · EPSS 0.1% · published 2026-07-27
  • CVE-2026-48843 — CVSS 7.2 high · EPSS 0.0% · published 2026-05-25
  • CVE-2026-87999 — CVSS 7.1 high · EPSS 0.2% · published 2026-09-09

Affected vendors

Threat activity

85 tracked threats cite CWE-918; the 25 most recent are listed.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.