Protection Mechanism Failure in NocoDB - CVE-2026-46553
Published: May 23, 2026
NocoDB
Detailed vulnerability description
The vulnerability allows a remote user to bypass the configured per-file size limit.
The vulnerability exists due to improper enforcement of size restrictions in the upload-by-URL attachment handling when processing upload-by-URL requests and data: URIs. A remote user can supply a URL or data: URI referencing an oversized file to bypass the configured per-file size limit.
Exploitation requires upload permission.