CVE-2026-33221

Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload handler trusts the client-provided Content-Type header without performing server-side MIME type detection. This allows an attacker to upload files with an arbitrary MIME type, bypassing any MIME-type-based restrictions configured on storage buckets. This issue has been patched in version 0.12.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nhost:storage:*:*:*:*:*:*:*:*

History

03 Jun 2026, 14:21

Type Values Removed Values Added
References () https://github.com/nhost/nhost/commit/c4bd53f042d7f568e567e18e2665af81660fce85 - () https://github.com/nhost/nhost/commit/c4bd53f042d7f568e567e18e2665af81660fce85 - Patch
References () https://github.com/nhost/nhost/pull/4018 - () https://github.com/nhost/nhost/pull/4018 - Issue Tracking, Patch
References () https://github.com/nhost/nhost/releases/tag/storage%400.12.0 - () https://github.com/nhost/nhost/releases/tag/storage%400.12.0 - Product, Release Notes
References () https://github.com/nhost/nhost/security/advisories/GHSA-g9f6-9775-hffm - () https://github.com/nhost/nhost/security/advisories/GHSA-g9f6-9775-hffm - Mitigation, Vendor Advisory
First Time Nhost
Nhost storage
CPE cpe:2.3:a:nhost:storage:*:*:*:*:*:*:*:*
Summary
  • (es) Nhost es una alternativa de código abierto a Firebase con GraphQL. Antes de la versión 0.12.0, el gestor de carga de archivos del servicio de almacenamiento confía en el encabezado Content-Type proporcionado por el cliente sin realizar detección de tipo MIME en el servidor. Esto permite a un atacante subir archivos con un tipo MIME arbitrario, eludiendo cualquier restricción basada en el tipo MIME configurada en los buckets de almacenamiento. Este problema ha sido parcheado en la versión 0.12.0.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

20 Mar 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 23:16

Updated : 2026-06-03 14:21


NVD link : CVE-2026-33221

Mitre link : CVE-2026-33221

CVE.ORG link : CVE-2026-33221


JSON object : View

Products Affected

nhost

  • storage
CWE
CWE-343

Predictable Value Range from Previous Values

CWE-345

Insufficient Verification of Data Authenticity