Threats Tagged 'cwe-918'
View all threats tagged with 'cwe-918'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-918'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19246: Server-Side Request Forgery in HKUDS nanobotCVE-2026-19246 0 A server-side request forgery (SSRF) vulnerability exists in HKUDS nanobot up to version 0.2.1 in the function _download_image_data_url within nanobot/providers/image_generation.py. This vulnerability allows remote attackers to induce the server to make unintended requests. A patch addressing this issue is available on the main branch and planned for release in version 0.3.1. The vulnerability has a CVSS score of 6.3, indicating a medium severity level. Join the discussion | GCVE Database | 08/07/2026, 21:00:14 UTC Added: 08/08/2026, 14:52:01 UTC |
CVE-2026-47660: CWE-522: Insufficiently Protected Credentials in aehrc pathlingCVE-2026-47660 0 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated against `pathling.bulkSubmit.allowableSources`. When present, the bulk-submit OAuth flow trusts metadata and the returned `token_endpoint` from the caller-chosen location, then builds outbound OAuth client authentication directly from the submitter's stored credentials. This is fixed in Pathling Server 2.0.0. Join the discussion | CVE Database V5 | 08/07/2026, 19:57:24 UTC Added: 08/07/2026, 21:12:02 UTC |
CVE-2026-47664: CWE-20: Improper Input Validation in aehrc pathlingCVE-2026-47664 0 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `exportUrl` and uses it as the remote FHIR Bulk Export endpoint without constraining it to a trusted source. When PNP credentials are configured, Pathling builds a credentialed bulk-export client targeting the caller-chosen host, downloads manifest-selected files, and then reclassifies those staged files as trusted local `file://` imports - bypassing the configured `allowableSources` allowlist that protects the ordinary `$import` operation. This is fixed in Pathling Server 2.0.0. As a workaround, disable the `$import-pnp` operation (`pathling.operations.importPnpEnabled=false`) or do not configure PNP credentials. Join the discussion | CVE Database V5 | 08/07/2026, 20:28:06 UTC Added: 08/07/2026, 20:56:45 UTC |
CVE-2026-47662: CWE-20: Improper Input Validation in aehrc pathlingCVE-2026-47662 0 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller with only coarse operation authorities to act on attacker-chosen resource families because those entrypoints do not consistently enforce the documented per-resource `read` and `write` authorities. The documented authorization model requires an operation authority (e.g. `pathling:search`) to be paired with the matching per-resource `read` or `write` authority (e.g. `pathling:read:Patient`). Delete and batch are documented to require write authority for all referenced resource types. However, typed search, update, and related handlers are annotated only with `@OperationAccess(...)` and act on the provider-selected resource type without checking the corresponding per-resource authority. This is fixed in Pathling Server 2.0.0. Join the discussion | CVE Database V5 | 08/07/2026, 20:23:20 UTC Added: 08/07/2026, 20:27:00 UTC |
CVE-2026-47659: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in aehrc pathlingCVE-2026-47659 0 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a caller who can obtain any valid async export job ID to supply `file` parameter values containing path traversal sequences. The handler verifies only the supplied `job` and never normalises or confines the requested `file` path to that job's `jobs/<jobId>` directory before opening it as a filesystem resource. Because async export scratch space lives under the same warehouse database root as persisted resource tables, an attacker can use their own export job to read other files from the warehouse. This is fixed in Pathling Server 2.0.0. The `$result` handler now resolves and canonicalizes the requested file path and rejects any request that escapes the job's `jobs/<jobId>` directory. As an interim mitigation, disable the async export operations (`pathling.operations.exportEnabled`, `patientExportEnabled`, `groupExportEnabled`, `bulkSubmitEnabled`) or enable authentication and restrict export capability to trusted callers. Join the discussion | CVE Database V5 | 08/07/2026, 19:44:00 UTC Added: 08/07/2026, 19:56:45 UTC |
CVE-2026-17597: CWE-918 Server-Side Request Forgery (SSRF) in Sonatype Nexus Repository 3CVE-2026-17597 0 Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network connections to internal or otherwise restricted network addresses. Differences in the server's response could be used to infer whether internal hosts and ports are reachable. This issue affects Nexus Repository 3 CE/Pro versions up to and including 3.94.1, and is fixed in version 3.95.0. Join the discussion | CVE Database V5 | 08/07/2026, 18:31:44 UTC Added: 08/07/2026, 16:26:45 UTC |
CVE-2026-16027: CWE-918 Server-Side request forgery (SSRF) in Revenue Administration E-SignatureCVE-2026-16027 0 Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0. Join the discussion | GCVE Database | 08/07/2026, 07:14:12 UTC Added: 08/07/2026, 15:17:42 UTC |
CVE-2026-54207: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54207 0 Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables au-thenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524. Join the discussion | GCVE Database | 08/07/2026, 09:45:18 UTC Added: 08/07/2026, 15:17:33 UTC |
CVE-2026-15570: CWE-918 Server-Side request forgery (SSRF) in Vestel Telefunken TE24553B45V2DZ Smart TVCVE-2026-15570 0 An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded browser to issue requests to unintended loopback/internal destinations, including 127.0.0.1 addresses. In demonstrated scenarios, requests initiated through the SmartCenter browserseturl mechanism could reach an internal service and receive a successful response, although the same destination was not reachable through normal browser navigation. The issue affects firmware version V2.78.0.0 and is fixed in firmware version V2.85.2.0. Join the discussion | CVE Database V5 | 08/07/2026, 15:33:18 UTC Added: 08/07/2026, 13:56:58 UTC |
CVE-2026-54207: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54207 0 Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables au-thenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524. Join the discussion | CVE Database V5 | 08/07/2026, 09:45:18 UTC Added: 08/07/2026, 10:12:15 UTC |
Showing 1 to 10 of 156 results