# CWE-918: Server-Side Request Forgery (SSRF)

**KEV-linked**

> As of 2026-10-05, CWE-918 (SSRF) underlies 76 CVEs tracked by Threadlinqs, 10 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 85 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-918?

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

CWE-918 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: AI/ML; Technology: Web Server.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/918.html) (CWE-918 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality** — Read Application Data
- **Integrity** — Execute Unauthorized Code or Commands
- **Access Control** — Bypass Protection Mechanism. By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the…

_Source: MITRE CWE, common consequences._

## How CWE-918 is exploited in the wild

Threadlinqs maps 76 CVEs to CWE-918, published between 2021-03-03 and 2026-10-03. 10 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 4 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 11 critical, 28 high, 27 medium, 3 low. The highest EPSS score in the set is 97.5% (CVE-2025-61884), the modelled probability of exploitation in the next 30 days. 85 tracked threats reference CWE-918 directly or through a CVE it covers; the most recent is “AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019” (2026-10-03). Affected products concentrate in Microsoft (7), IBM (3), jfrog (3), among 58 vendors in total.

## Vulnerabilities (CVEs)

Showing 40 of 76 CVEs mapped to CWE-918, CISA KEV first, then by CVSS score.

- [CVE-2026-83548](https://intel.threadlinqs.com/cve/CVE-2026-83548) — CISA KEV · CVSS 10 critical · EPSS 0.2% · published 2026-09-01
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409) — CISA KEV · CVSS 10 critical · published 2026-07-14
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473) — CISA KEV · CVSS 9.1 critical · EPSS 94.1% · published 2021-07-14
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855) — CISA KEV · CVSS 9.1 critical · EPSS 93.9% · published 2021-03-03
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040) — CISA KEV · CVSS 8.8 high · EPSS 94.1% · published 2022-10-03
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230) — CISA KEV · CVSS 8.6 high · EPSS 41.6% · published 2026-06-03
- [CVE-2024-21893](https://intel.threadlinqs.com/cve/CVE-2024-21893) — CISA KEV · CVSS 8.2 high · EPSS 94.3% · published 2024-01-31
- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884) — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
- [CVE-2021-22054](https://intel.threadlinqs.com/cve/CVE-2021-22054) — CISA KEV · CVSS 7.5 high · EPSS 93.8% · published 2021-12-17
- [CVE-2021-39935](https://intel.threadlinqs.com/cve/CVE-2021-39935) — CISA KEV · CVSS 6.8 medium · EPSS 41.4% · published 2021-12-13
- [CVE-2026-48331](https://intel.threadlinqs.com/cve/CVE-2026-48331) — CVSS 10 critical · published 2026-08-03
- [CVE-2026-45499](https://intel.threadlinqs.com/cve/CVE-2026-45499) — CVSS 9.9 critical · EPSS 0.6% · published 2026-07-02
- [CVE-2026-57100](https://intel.threadlinqs.com/cve/CVE-2026-57100) — CVSS 9.9 critical · published 2026-07-02
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022) — CVSS 9.8 critical · EPSS 83.9% · published 2023-11-28
- [CVE-2026-22874](https://intel.threadlinqs.com/cve/CVE-2026-22874) — CVSS 9.6 critical · EPSS 0.4% · published 2026-07-03
- [CVE-2026-75332](https://intel.threadlinqs.com/cve/CVE-2026-75332) — CVSS 9.1 critical · EPSS 0.1% · published 2026-08-26
- [CVE-2026-75340](https://intel.threadlinqs.com/cve/CVE-2026-75340) — CVSS 9.1 critical · EPSS 0.1% · published 2026-08-26
- [CVE-2026-5921](https://intel.threadlinqs.com/cve/CVE-2026-5921) — CVSS 8.9 high · EPSS 0.0% · published 2026-04-21
- [CVE-2026-82097](https://intel.threadlinqs.com/cve/CVE-2026-82097) — CVSS 8.8 high · EPSS 0.3% · published 2026-09-10
- [CVE-2026-72848](https://intel.threadlinqs.com/cve/CVE-2026-72848) — CVSS 8.6 high · EPSS 0.4% · published 2026-08-20
- [CVE-2026-62242](https://intel.threadlinqs.com/cve/CVE-2026-62242) — CVSS 8.6 high · EPSS 0.2% · published 2026-07-13
- [CVE-2026-73247](https://intel.threadlinqs.com/cve/CVE-2026-73247) — CVSS 8.6 high · published 2026-08-11
- [CVE-2026-72860](https://intel.threadlinqs.com/cve/CVE-2026-72860) — CVSS 8.5 high · EPSS 0.2% · published 2026-08-20
- [CVE-2026-62197](https://intel.threadlinqs.com/cve/CVE-2026-62197) — CVSS 8.5 high · EPSS 0.2% · published 2026-07-13
- [CVE-2026-77348](https://intel.threadlinqs.com/cve/CVE-2026-77348) — CVSS 8.2 high · EPSS 0.2% · published 2026-08-31
- [CVE-2026-9312](https://intel.threadlinqs.com/cve/CVE-2026-9312) — CVSS 8.2 high · EPSS 0.0% · published 2026-05-27
- [CVE-2026-69855](https://intel.threadlinqs.com/cve/CVE-2026-69855) — CVSS 7.7 high · EPSS 0.4% · published 2026-08-20
- [CVE-2026-33626](https://intel.threadlinqs.com/cve/CVE-2026-33626) — CVSS 7.5 high · EPSS 2.9% · published 2026-04-20
- [CVE-2026-85917](https://intel.threadlinqs.com/cve/CVE-2026-85917) — CVSS 7.5 high · EPSS 0.5% · published 2026-09-17
- [CVE-2026-55391](https://intel.threadlinqs.com/cve/CVE-2026-55391) — CVSS 7.5 high · published 2026-07-28
- [CVE-2026-62240](https://intel.threadlinqs.com/cve/CVE-2026-62240) — CVSS 7.4 high · EPSS 0.2% · published 2026-07-13
- [CVE-2026-9006](https://intel.threadlinqs.com/cve/CVE-2026-9006) — CVSS 7.4 high · EPSS 0.2% · published 2026-06-22
- [CVE-2026-82957](https://intel.threadlinqs.com/cve/CVE-2026-82957) — CVSS 7.3 high · EPSS 0.3% · published 2026-08-31
- [CVE-2026-19374](https://intel.threadlinqs.com/cve/CVE-2026-19374) — CVSS 7.3 high · EPSS 0.3% · published 2026-08-09
- [CVE-2026-19753](https://intel.threadlinqs.com/cve/CVE-2026-19753) — CVSS 7.3 high · EPSS 0.2% · published 2026-08-13
- [CVE-2026-86539](https://intel.threadlinqs.com/cve/CVE-2026-86539) — CVSS 7.2 high · EPSS 0.2% · published 2026-09-07
- [CVE-2026-61953](https://intel.threadlinqs.com/cve/CVE-2026-61953) — CVSS 7.2 high · EPSS 0.1% · published 2026-07-27
- [CVE-2026-65442](https://intel.threadlinqs.com/cve/CVE-2026-65442) — CVSS 7.2 high · EPSS 0.1% · published 2026-07-27
- [CVE-2026-48843](https://intel.threadlinqs.com/cve/CVE-2026-48843) — CVSS 7.2 high · EPSS 0.0% · published 2026-05-25
- [CVE-2026-87999](https://intel.threadlinqs.com/cve/CVE-2026-87999) — CVSS 7.1 high · EPSS 0.2% · published 2026-09-09

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 7 CVEs
- [IBM](https://intel.threadlinqs.com/vendors/ibm) — 3 CVEs
- [jfrog](https://intel.threadlinqs.com/vendors/jfrog) — 3 CVEs
- [open-webui](https://intel.threadlinqs.com/vendors/open-webui) — 3 CVEs
- **Github** — 2 CVEs
- [SonicWall](https://intel.threadlinqs.com/vendors/sonicwall) — 2 CVEs
- **0717376** — 1 CVE
- **ASUS** — 1 CVE
- [Adobe](https://intel.threadlinqs.com/vendors/adobe) — 1 CVE
- **Anyscale** — 1 CVE
- [Capgo](https://intel.threadlinqs.com/vendors/capgo) — 1 CVE
- [Cisco](https://intel.threadlinqs.com/vendors/cisco) — 1 CVE

## Threat activity

85 tracked threats cite CWE-918; the 25 most recent are listed.

- [AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019](https://intel.threadlinqs.com/threat/TL-2026-2860) — CRITICAL · 2026-10-03
- [Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL · 2026-10-02
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack phishing](https://intel.threadlinqs.com/threat/TL-2026-2642) — HIGH · 2026-09-24
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL · 2026-09-23
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)](https://intel.threadlinqs.com/threat/TL-2026-2563) — CRITICAL · 2026-09-18
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2515) — HIGH · 2026-09-15
- [CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2354) — CRITICAL · 2026-09-06
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL · 2026-09-06
- [SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2307) — CRITICAL · 2026-09-03
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto](https://intel.threadlinqs.com/threat/TL-2026-2310) — HIGH · 2026-09-03
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL · 2026-08-26
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH · 2026-08-26
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — CRITICAL · 2026-08-23
- [CVE-2026-64849 — MLflow Server-Side Request Forgery (SSRF) Vulnerability in Model Registry Webhooks](https://intel.threadlinqs.com/threat/TL-2026-2077) — CRITICAL · 2026-08-19
- [AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape, PyPI Supply-Chain Package, and Artifactory Zero-Day Abuse](https://intel.threadlinqs.com/threat/TL-2026-2030) — HIGH · 2026-08-16
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)](https://intel.threadlinqs.com/threat/TL-2026-1987) — CRITICAL · 2026-08-11
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails](https://intel.threadlinqs.com/threat/TL-2026-1930) — HIGH · 2026-08-07
- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2](https://intel.threadlinqs.com/threat/TL-2026-2893) — HIGH · 2026-08-06
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django](https://intel.threadlinqs.com/threat/TL-2026-1891) — CRITICAL · 2026-08-05
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448)](https://intel.threadlinqs.com/threat/TL-2026-1790) — CRITICAL · 2026-07-31
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — CRITICAL · 2026-07-28
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — HIGH · 2026-07-26
- [AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh)](https://intel.threadlinqs.com/threat/TL-2026-1686) — MEDIUM · 2026-07-25
- [Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLi](https://intel.threadlinqs.com/threat/TL-2026-1666) — CRITICAL · 2026-07-24
- [Command Injection Vulnerabilities in Bing Images Processing Pipeline (CVE-2026-32194, CVE-2026-32191, CVE-2026-21536) — RCE as NT AUTHORITY\\SYSTEM](https://intel.threadlinqs.com/threat/TL-2026-1677) — CRITICAL · 2026-07-24

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-441 Confused Deputy](https://intel.threadlinqs.com/cwe/CWE-441)
- [CWE-610](https://cwe.mitre.org/data/definitions/610.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-918
Source definition: https://cwe.mitre.org/data/definitions/918.html
Detection rules and IOCs for threats exploiting CWE-918 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
