Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1690
  • PyPI/nautobot-ssot
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1689
  • PyPI/nautobot
Nautobot may allows uploaded media files to be accessible without authentication 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-1688
  • PyPI/nautobot
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1686
  • PyPI/nautobot
nautobot has reflected Cross-site Scripting potential in all object list views 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1687
  • PyPI/nautobot
Unauthenticated views may expose information to anonymous users 07 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-2228
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2227
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-2226
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2225
  • PyPI/nautobot
See record for full details 28 May
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-p3hx-pwf3-j8wr
  • PyPI/nautobot
Nautobot: GitRepository.current_head field should not be writable through REST API 13 May
  • Fix available
  • Severity - 7.1 (High)
GHSA-c35q-vxrp-ph26
  • PyPI/nautobot
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) 13 May
  • Fix available
  • Severity - 8.5 (High)
GHSA-qrpw-gjvh-x5gm
  • PyPI/nautobot
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) 13 May
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-wpxj-44w3-2j6x
  • PyPI/nautobot
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference 13 May
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-xmpv-j7p2-j873
  • PyPI/nautobot
Nautobot: Management of users via REST API does not apply configured password validators 31 Mar
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2026-2224
  • PyPI/nautobot
See record for full details 31 Mar
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-535g-62r7-cx6v
  • PyPI/nautobot-ssot
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL 21 Oct 2025
  • Fix available
  • Severity - 5.3 (Medium)