Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in 2.4.33 and 3.1.2.
References
| Link | Resource |
|---|---|
| https://github.com/nautobot/nautobot/commit/16aa4aa9796ab7a31c4d615ec945e1f16d8c77c4 | Patch |
| https://github.com/nautobot/nautobot/commit/7324c8f0d8c7245fbc691e15d729adc2d2707d08 | Patch |
| https://github.com/nautobot/nautobot/releases/tag/v2.4.33 | Product Release Notes |
| https://github.com/nautobot/nautobot/releases/tag/v3.1.2 | Product Release Notes |
| https://github.com/nautobot/nautobot/security/advisories/GHSA-c35q-vxrp-ph26 | Mitigation Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-28 18:16
Updated : 2026-06-17 10:51
NVD link : CVE-2026-44797
Mitre link : CVE-2026-44797
CVE.ORG link : CVE-2026-44797
JSON object : View
Products Affected
networktocode
- nautobot
CWE
CWE-918
Server-Side Request Forgery (SSRF)
