Nautobot是Nautobot个人开发者的一个网络自动化平台。 Nautobot 2.4.33之前版本和3.1.2之前版本存在代码问题漏洞,该漏洞源于Webhook数据模型和相关功能集可被具有足够权限的用户配置为向不应允许的主机和IP地址发送请求,导致类似服务端请求伪造的行为。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44798 | 7.1 HIGH | Nautobot: GitRepository.current_head field should not be writable through REST API |
| CVE-2026-44796 | 6.5 MEDIUM | Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular |
| CVE-2026-44794 | 5.4 MEDIUM | Nautobot: REST API permits creation of GenericForeignKey references to objects that the us |
No comments yet