Inefficient regular expression complexity in Nautobot - CVE-2026-44796
Published: May 11, 2026
Nautobot
Nautobot
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in object bulk rename UI endpoints when processing a crafted regular expression in the find field with the use_regex flag enabled. A remote user can send a specially crafted request to cause a denial of service.
The issue can result in application-wide impact.