Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in 2.4.33 and 3.1.2.
References
| Link | Resource |
|---|---|
| https://github.com/nautobot/nautobot/commit/16aa4aa9796ab7a31c4d615ec945e1f16d8c77c4 | Patch |
| https://github.com/nautobot/nautobot/commit/7324c8f0d8c7245fbc691e15d729adc2d2707d08 | Patch |
| https://github.com/nautobot/nautobot/releases/tag/v2.4.33 | Product Release Notes |
| https://github.com/nautobot/nautobot/releases/tag/v3.1.2 | Product Release Notes |
| https://github.com/nautobot/nautobot/security/advisories/GHSA-c35q-vxrp-ph26 | Mitigation Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 May 2026, 13:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Networktocode nautobot
Networktocode |
|
| CPE | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* | |
| References | () https://github.com/nautobot/nautobot/commit/16aa4aa9796ab7a31c4d615ec945e1f16d8c77c4 - Patch | |
| References | () https://github.com/nautobot/nautobot/commit/7324c8f0d8c7245fbc691e15d729adc2d2707d08 - Patch | |
| References | () https://github.com/nautobot/nautobot/releases/tag/v2.4.33 - Product, Release Notes | |
| References | () https://github.com/nautobot/nautobot/releases/tag/v3.1.2 - Product, Release Notes | |
| References | () https://github.com/nautobot/nautobot/security/advisories/GHSA-c35q-vxrp-ph26 - Mitigation, Patch, Vendor Advisory |
28 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 18:16
Updated : 2026-05-29 13:26
NVD link : CVE-2026-44797
Mitre link : CVE-2026-44797
CVE.ORG link : CVE-2026-44797
JSON object : View
Products Affected
networktocode
- nautobot
CWE
CWE-918
Server-Side Request Forgery (SSRF)
