Server-Side Request Forgery (SSRF) in Nautobot - #VU130971
Published: May 11, 2026
Nautobot
Nautobot
Description
The vulnerability allows a remote user to perform server-side requests to unintended hosts and IP addresses.
The vulnerability exists due to server-side request forgery in the Webhook data model and associated feature set when processing user-defined webhook destinations. A remote user can configure a webhook to send requests to disallowed destinations to perform server-side requests to unintended hosts and IP addresses.
Exploitation requires add or change permissions for the Webhook data model.