Dependency scanning
Check whether nautobot is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-83805
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
CVE-2026-83801
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
CVE-2024-34707
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
CVE-2024-32979
nautobot has reflected Cross-site Scripting potential in all object list views
CVE-2024-29199
Unauthenticated views may expose information to anonymous users
CVE-2024-23345
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
CVE-2023-50263
Unauthenticated db-file-storage views
CVE-2023-46128
Nautobot vulnerable to exposure of hashed user passwords via REST API
CVE-2026-34203
Nautobot: Management of users via REST API does not apply configured password validators
CVE-2026-44798
Nautobot: GitRepository.current_head field should not be writable through REST API
CVE-2026-44797
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
CVE-2026-44794
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
CVE-2026-44796
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVE-2026-44798
CVE-2026-44798
CVE-2026-44797
CVE-2026-44797
CVE-2026-44796
CVE-2026-44796
CVE-2026-34203
CVE-2026-34203
CVE-2026-44794
CVE-2026-44794
CVE-2025-49143
Nautobot may allows uploaded media files to be accessible without authentication
CVE-2024-34707
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
CVE-2025-49143
Nautobot may allows uploaded media files to be accessible without authentication
CVE-2024-29199
Unauthenticated views may expose information to anonymous users
CVE-2024-32979
nautobot has reflected Cross-site Scripting potential in all object list views
CVE-2024-36112
CVE-2024-36112
CVE-2024-36112
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
CVE-2025-49142
CVE-2025-49142
CVE-2025-49142
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
CVE-2023-51649
Nautobot missing object-level permissions enforcement when running Job Buttons
CVE-2023-50263
CVE-2023-50263
CVE-2023-51649
CVE-2023-51649
CVE-2023-48705
Cross-site Scripting potential in custom links, job buttons, and computed fields
CVE-2023-48705
CVE-2023-48705
CVE-2023-25657
Nautobot vulnerable to remote code execution via Jinja2 template rendering
CVE-2024-23345
CVE-2024-23345
CVE-2023-46128
CVE-2023-46128
CVE-2023-25657
CVE-2023-25657
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes