CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Server-side request forgery vulnerabilities

SSRF109 advisories29 exploitedlatest 2026-08-25

Server-side request forgery tricks a server into making requests on the attacker’s behalf — reaching internal services, cloud metadata endpoints, or admin APIs that are unreachable from outside. In cloud environments SSRF is a credential-theft primitive, and it chains naturally with other bugs into full compromise.

Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged server-side request forgery, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.

Latest server-side request forgery advisories

Other vulnerability classes

Remote code execution (2023)Privilege escalation (1548)Authentication bypass (1066)Denial of service (2105)Information disclosure (1543)Memory corruption (1308)Path traversal (235)Code injection (343)Cross-site scripting (315)Unsafe deserialization (83)SQL injection (143)
New server-side request forgery advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.