CVE-2026-44797
גבוהה 8.5
תיאור (מקור, אנגלית)
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in 2.4.33 and 3.1.2.
מדדים
- CVSS 3.1
-
8.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-6/8/2026
- CWE
- CWE-918
מוצרים מושפעים
networktocode: nautobot
קישורים
- https://github.com/nautobot/nautobot/security/advisories/GHSA-c35q-vxrp-ph26 MitigationPatchVendor Advisory
- https://github.com/nautobot/nautobot/commit/16aa4aa9796ab7a31c4d615ec945e1f16d… Patch
- https://github.com/nautobot/nautobot/commit/7324c8f0d8c7245fbc691e15d729adc2d2… Patch
- https://github.com/nautobot/nautobot/releases/tag/v2.4.33 ProductRelease Notes
- https://github.com/nautobot/nautobot/releases/tag/v3.1.2 ProductRelease Notes