top of page
perceptive_background_267k.jpg

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications

Nautobot, a Network Source of Truth and Network Automation Platform, contains a server-side request forgery (SSRF) vulnerability in versions prior to 2.4.33 and 3.1.2. The vulnerability exists in the Webhook data model and associated feature set, allowing users with sufficient access to perform unauthorized requests to various hosts and IP addresses. This could enable attackers to access internal systems or perform reconnaissance on internal networks. The vulnerability has been patched in versions 2.4.33 and 3.1.2, with fixes available through GitHub commits and security advisories.

Technical details

Mitigation steps:

Affected products:

Nautobot

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page