cbcvebase.
CVE-2026-24767
published 2026-01-28

CVE-2026-24767: NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the…

PriorityP339medium6.4CVSS 3.1
AVNACLPRLUINSCCLILAN
EPSS
0.20%
9.8th percentile
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the `uploadViaURL` functionality due to an unprotected `HEAD` request. While the subsequent file retrieval logic correctly enforces SSRF protections, the initial metadata request executes without validation. This allows limited outbound requests to arbitrary URLs before SSRF controls are applied. Version 0.301.0 contains a patch for the issue.

Affected

5 ranges
VendorProductVersion rangeFixed in
github.comlxc_incus_v6_cmd_incusd>= 0 < 7.0.07.0.0
linuxcontainersincus< 7.0.07.0.0
lxcincus< 7.0.07.0.0
nocodbnocodb< 0.301.00.301.0
nocodbnocodb>= 0 < 0.301.00.301.0

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
ghsa6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.