Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mvvv-v22x-xqwp | NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins |
Wed, 13 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nocobase:nocobase:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nocobase
Nocobase nocobase |
|
| Vendors & Products |
Nocobase
Nocobase nocobase |
|
| Metrics |
ssvc
|
Sat, 18 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch. | |
| Title | NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-20T14:56:12.829Z
Reserved: 2026-04-10T22:50:01.358Z
Link: CVE-2026-40346
Updated: 2026-04-20T14:42:38.711Z
Status : Analyzed
Published: 2026-04-18T00:16:38.360
Modified: 2026-05-13T20:53:48.530
Link: CVE-2026-40346
No data.
OpenCVE Enrichment
Updated: 2026-04-20T14:59:02Z
Github GHSA