CVE-2026-24767
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.9EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
28 ene 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the `uploadViaURL` functionality due to an unprotected `HEAD` request. While the subsequent file retrieval logic correctly enforces SSRF protections, the initial metadata request executes without validation. This allows limited outbound requests to arbitrary URLs before SSRF controls are applied. Version 0.301.0 contains a patch for the issue.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Productos afectados
nocodb · nocodb¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →