Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-95ff-46g6-6gw9 | NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS |
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:* |
Fri, 30 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nocodb
Nocodb nocodb |
|
| Vendors & Products |
Nocodb
Nocodb nocodb |
Wed, 28 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail application-wide until server restart. While the pollution technically bypasses SUPER_ADMIN authorization checks, no practical privileged actions can be performed because database operations fail immediately after pollution. Version 0.301.0 patches the issue. | |
| Title | NocoDB Vulnerable to Prototype Pollution in Connection Test Endpoint, Leading to DoS | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-29T18:01:30.160Z
Reserved: 2026-01-26T21:06:47.868Z
Link: CVE-2026-24766
Updated: 2026-01-29T16:03:36.099Z
Status : Analyzed
Published: 2026-01-28T21:16:12.103
Modified: 2026-02-04T20:06:08.177
Link: CVE-2026-24766
No data.
OpenCVE Enrichment
Updated: 2026-04-18T01:45:33Z
Github GHSA