Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nautobot — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in nautobot, with AI-generated Chinese analysis, references, and POCs.

This page details the Common Weakness Enumerations (CWE) affecting Nautobot, a network and infrastructure automation platform developed by Digital Realty. It aggregates security vulnerabilities identified in this product, covering disclosures released between 2021 and 2024. The content includes a comprehensive history of security issues reported against Nautobot, ranging from critical remote code execution flaws to less severe information disclosure and permission bypass weaknesses. By reviewing this collection, users can track a vendor's advisory history to understand the pace and nature of security remediation efforts. Additionally, the page allows for a deeper understanding of a specific weakness class by showing how it manifests within the Nautobot codebase and configuration. Security professionals can also look up a product's vulnerability history to assess long-term stability and the effectiveness of patch management practices. This data is structured to facilitate risk assessment, helping teams evaluate the current security posture of Nautobot installations relative to known industry threats. The aggregation does not include real-time scanning data but relies on publicly available vulnerability databases and official product advisories. It serves as a reference point for compliance officers and system administrators who need to verify if specific patches have been applied or if certain legacy versions remain exposed to known exploits. The focus remains strictly on factual security reporting without promotional commentary or vendor bias.

Vendor: nautobot

CVE IDTitleCVSSSeverityPublished
CVE-2026-44794 Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference CWE-862 5.4 Medium2026-05-28
CVE-2026-44796 Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) CWE-400 6.5 Medium2026-05-28
CVE-2026-44797 Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) CWE-918 8.5 High2026-05-28
CVE-2026-44798 Nautobot: GitRepository.current_head field should not be writable through REST API CWE-471 7.1 High2026-05-28
CVE-2026-34203 Nautobot: Management of users via REST API does not apply configured password validators CWE-521 2.7 Low2026-03-31
CVE-2025-49143 Nautobot may allows uploaded media files to be accessible without authentication CWE-200 7.5AIHighAI2025-06-10
CVE-2025-49142 Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating CWE-1336 8.1AIHighAI2025-06-10
CVE-2024-36112 Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects CWE-280 6.3 Medium2024-05-28
CVE-2024-34707 Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages CWE-79 7.5 High2024-05-13
CVE-2024-32979 Reflected Cross-site Scripting potential in all object list views in Nautobot CWE-79 7.5 High2024-05-01
CVE-2024-29199 Unauthenticated views may expose information to anonymous users CWE-200 3.7 Low2024-03-26
CVE-2024-23345 Nautobot has XSS potential in rendered Markdown fields CWE-79 7.1 High2024-01-22
CVE-2023-51649 Nautobot missing object-level permissions enforcement when running Job Buttons CWE-863 3.5 Low2023-12-22
CVE-2023-50263 Nautobot allows unauthenticated db-file-storage views CWE-200 3.7 Low2023-12-12
CVE-2023-48705 nautobot has XSS potential in custom links, job buttons, and computed fields CWE-79 7.1 High2023-11-22
CVE-2023-46128 Exposure of hashed user passwords via REST API in Nautobot CWE-200 6.5 Medium2023-10-24
CVE-2023-25657 Remote code execution in Jinja2 template rendering in Nautobot CWE-94 7.5 High2023-02-21

All 17 known CVE vulnerabilities affecting nautobot with full Chinese analysis, references, and POCs where available.