


Perceptive Security
SOC/SIEM Consultancy

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 19:09:38
Source:
nvd.nist.gov
Network Infrastructure, Enterprise Applications
Nautobot, a Network Source of Truth and Network Automation Platform, contains a server-side request forgery (SSRF) vulnerability in versions prior to 2.4.33 and 3.1.2. The vulnerability exists in the Webhook data model and associated feature set, allowing users with sufficient access to perform unauthorized requests to various hosts and IP addresses. This could enable attackers to access internal systems or perform reconnaissance on internal networks. The vulnerability has been patched in versions 2.4.33 and 3.1.2, with fixes available through GitHub commits and security advisories.
Technical details
Mitigation steps:
Affected products:
Nautobot
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44797
https://github.com/nautobot/nautobot/commit/16aa4aa9796ab7a31c4d615ec945e1f16d8c77c4
https://github.com/nautobot/nautobot/commit/7324c8f0d8c7245fbc691e15d729adc2d2707d08
https://github.com/nautobot/nautobot/releases/tag/v2.4.33
https://github.com/nautobot/nautobot/releases/tag/v3.1.2
https://github.com/nautobot/nautobot/security/advisories/GHSA-c35q-vxrp-ph26
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
