netbox-community has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-829 (3). Most affected products: devicetype-library (3), netbox (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-54752Critical· 9.6NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox53CVE-2026-54916High· 8.8NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox48CVE-2026-86175Medium· 6.5NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses48CVE-2026-54918Medium· 5.3NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox29CVE-2026-86176Medium· 4.3NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks24
netbox-community vulnerabilities
CVEs affecting netbox-community, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-54916High· 8.8NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests dire…
CVE-2026-54918Medium· 5.3NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…
CVE-2026-54752Critical· 9.6NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…
CVE-2026-86176Medium· 4.3NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks
NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through …
CVE-2026-86175Medium· 6.5PoCNetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses
NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backen…