Allocation of Resources Without Limits or Throttling in NocoDB - CVE-2026-46551
Published: May 23, 2026
NocoDB
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the v1/v2 attachment API upload-by-url path when downloading files from user-supplied URLs. A remote user can submit a URL referencing an arbitrarily large file to cause a denial of service.
The issue can exhaust disk space and lead to blocked database writes, log rotation failures, and application crashes.