nautobot vulnerabilities
CVEs whose affected-version data names the nautobot package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2026-44794Medium· 5.4Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
CVE-2026-44796Medium· 6.5Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVE-2026-44798High· 7.1Nautobot: GitRepository.current_head field should not be writable through REST API
Nautobot: GitRepository.current_head field should not be writable through REST API
CVE-2026-44797High· 8.5Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
CVE-2026-34203Low· 2.7Nautobot: Management of users via REST API does not apply configured password validators
Nautobot: Management of users via REST API does not apply configured password validators
CVE-2025-49143MediumNautobot may allows uploaded media files to be accessible without authentication
Nautobot may allows uploaded media files to be accessible without authentication
CVE-2024-34707High· 7.5Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
CVE-2024-32979High· 7.5nautobot has reflected Cross-site Scripting potential in all object list views
nautobot has reflected Cross-site Scripting potential in all object list views
CVE-2024-29199Low· 3.7Unauthenticated views may expose information to anonymous users
Unauthenticated views may expose information to anonymous users
CVE-2024-23345High· 7.1XSS potential in rendered Markdown fields (comments, description, notes, etc.)
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
CVE-2023-50263Low· 3.7Unauthenticated db-file-storage views
Unauthenticated db-file-storage views
CVE-2023-46128High· 7.7Nautobot vulnerable to exposure of hashed user passwords via REST API
Nautobot vulnerable to exposure of hashed user passwords via REST API