Back to Labs
Weakness (CWE)

CWE-918

Server-Side Request Forgery (SSRF)

About

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Common consequences

  • Confidentiality → Read Application Data
  • Integrity → Execute Unauthorized Code or Commands
  • Access Control → Bypass Protection Mechanism

CVEs with this weakness

Frequently asked questions

What is CWE-918?

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Common consequences Confidentiality → Read Application Data Integrity → Execute Unauthorized Code or Commands Access Control → Bypass Protection Mechanism

Which platforms does CWE-918 affect?

CWE-918 has been observed on: Web Based, AI/ML, Web Server.

How many CVEs does Rainforest track for CWE-918?

Rainforest Labs currently tracks 2 published CVEs mapped to CWE-918. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.