Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.
References
Configurations
No configuration.
History
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-16 21:17
NVD link : CVE-2026-92804
Mitre link : CVE-2026-92804
CVE.ORG link : CVE-2026-92804
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
