Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nautobot — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in nautobot, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation report for the Nautobot network infrastructure automation platform, focusing on common weakness classifications and associated security tags. It compiles a comprehensive list of known security flaws affecting Nautobot, covering reports published from the software's initial release through the most recent updates to ensure historical and current context are both represented. Here, users can track vendor advisories from the Nautobot community and maintainers to stay informed about emerging threats, understand the specific characteristics and impact of different weakness classes within the application's codebase, and look up the product's vulnerability history to assess risk exposure over time. The data includes details on affected versions, severity ratings, and remediation steps where available, providing a centralized resource for security analysts, system administrators, and DevOps engineers responsible for maintaining network infrastructure. By organizing these entries by weakness type and release date, the page facilitates rapid identification of relevant threats and supports informed decision-making regarding patching and mitigation strategies. This aggregation aims to reduce the friction in identifying and resolving security issues by presenting all known Nautobot vulnerabilities in one accessible location, thereby enhancing the overall security posture of deployments relying on this platform.

Vendor: nautobot

CVE IDTitleCVSSSeverityPublished
CVE-2026-44794 Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference CWE-862 5.4 Medium2026-05-28
CVE-2026-44796 Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) CWE-400 6.5 Medium2026-05-28
CVE-2026-44797 Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) CWE-918 8.5 High2026-05-28
CVE-2026-44798 Nautobot: GitRepository.current_head field should not be writable through REST API CWE-471 7.1 High2026-05-28
CVE-2026-34203 Nautobot: Management of users via REST API does not apply configured password validators CWE-521 2.7 Low2026-03-31
CVE-2025-49143 Nautobot may allows uploaded media files to be accessible without authentication CWE-200 7.5AIHighAI2025-06-10
CVE-2025-49142 Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating CWE-1336 8.1AIHighAI2025-06-10
CVE-2024-36112 Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects CWE-280 6.3 Medium2024-05-28
CVE-2024-34707 Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages CWE-79 7.5 High2024-05-13
CVE-2024-32979 Reflected Cross-site Scripting potential in all object list views in Nautobot CWE-79 7.5 High2024-05-01
CVE-2024-29199 Unauthenticated views may expose information to anonymous users CWE-200 3.7 Low2024-03-26
CVE-2024-23345 Nautobot has XSS potential in rendered Markdown fields CWE-79 7.1 High2024-01-22
CVE-2023-51649 Nautobot missing object-level permissions enforcement when running Job Buttons CWE-863 3.5 Low2023-12-22
CVE-2023-50263 Nautobot allows unauthenticated db-file-storage views CWE-200 3.7 Low2023-12-12
CVE-2023-48705 nautobot has XSS potential in custom links, job buttons, and computed fields CWE-79 7.1 High2023-11-22
CVE-2023-46128 Exposure of hashed user passwords via REST API in Nautobot CWE-200 6.5 Medium2023-10-24
CVE-2023-25657 Remote code execution in Jinja2 template rendering in Nautobot CWE-94 7.5 High2023-02-21

All 17 known CVE vulnerabilities affecting nautobot with full Chinese analysis, references, and POCs where available.