Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4111
  • PyPI/nautobot
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs 4 days ago
  • Fix available
  • Severity - 6.4 (Medium)
PYSEC-2026-4110
  • PyPI/nautobot
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text 4 days ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-q4c5-2j6f-r476
  • PyPI/nautobot
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs 22 Sep
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-56v6-2fhr-wxgq
  • PyPI/nautobot
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text 22 Sep
  • Fix available
  • Severity - 5.4 (Medium)
PYSEC-2026-1690
  • PyPI/nautobot-ssot
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1689
  • PyPI/nautobot
Nautobot may allows uploaded media files to be accessible without authentication 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-1688
  • PyPI/nautobot
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1686
  • PyPI/nautobot
nautobot has reflected Cross-site Scripting potential in all object list views 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1687
  • PyPI/nautobot
Unauthenticated views may expose information to anonymous users 07 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-2228
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2227
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-2226
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2225
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-p3hx-pwf3-j8wr
  • PyPI/nautobot
Nautobot: GitRepository.current_head field should not be writable through REST API 13 May
  • Fix available
  • Severity - 7.1 (High)
GHSA-c35q-vxrp-ph26
  • PyPI/nautobot
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) 13 May
  • Fix available
  • Severity - 8.5 (High)
GHSA-qrpw-gjvh-x5gm
  • PyPI/nautobot
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) 13 May
  • Fix available
  • Severity - 6.5 (Medium)