CVE-2026-44797

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in 2.4.33 and 3.1.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-28 18:16

Updated : 2026-06-17 10:51


NVD link : CVE-2026-44797

Mitre link : CVE-2026-44797

CVE.ORG link : CVE-2026-44797


JSON object : View

Products Affected

networktocode

  • nautobot
CWE
CWE-918

Server-Side Request Forgery (SSRF)