Nautobot, a Network Source of Truth and Network Automation Platform, contains a server-side request forgery (SSRF) vulnerability in its Webhook data model. Users with sufficient privileges can configure webhooks to target restricted internal hosts and IP addresses, enabling unauthorized outbound requests. The vulnerability stems from insufficient validation of webhook destination URLs, allowing attackers [truncated]
Nautobot, a Network Source of Truth and Network Automation Platform, contains a denial-of-service vulnerability in its UI object-bulk-rename endpoints (e.g., /dcim/interfaces/rename/). Prior to versions 2.4.33 and 3.1.2, authenticated users with access to these endpoints could trigger application-wide DoS by submitting maliciously crafted regular expressions in the find field when the use_regex flag is en [truncated]
Nautobot, a Network Source of Truth and Network Automation Platform, contains an authorization bypass vulnerability in its REST API. Prior to versions 2.4.33 and 3.1.2, when creating or updating objects that use GenericForeignKey references (a Django pattern allowing polymorphic relationships to multiple content types), the API failed to enforce user 'view' permissions when validating object references. T [truncated]
CVE-2026-34203 is a low-severity vulnerability in Nautobot, a Network Source of Truth and Network Automation Platform. The issue arises from inadequate password validation when creating or editing users via the REST API. By default, Nautobot relies on Django's AUTH_PASSWORD_VALIDATORS setting, which is an empty list, meaning no specific password rules are enforced. However, organizations can configure cus [truncated]