216.73.217.22

CVE-2026-40346

· Published 18/04/2026 00:16 · Modified 18/04/2026 00:16

Labels: CVE-2026-40346 2026-04-18CVE-2026-40346CWE-918[email protected]

Essential information

Published
18/04/2026 00:16
Modified
18/04/2026 00:16
Author
Creator
CVSS
6.4 MEDIUM (v3) 6.4 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
noco / nocobase cpe:2.3:a:noco:nocobase:<2.0.37:*:*:*:*:*:*:*

References