CVE-2026-47382 Details
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-supplied database host without resolving and range-checking the destination, so private and link-local addresses (including IPv4-mapped IPv6 forms and localhost) reached the driver. This vulnerability is fixed in 2026.05.1.
A server-side request forgery (SSRF) vulnerability has been identified in NocoDB versions through 2026.05.0. The issue arises in the connection-test endpoint, which opened a raw TCP socket to user-supplied database hosts without proper validation. This lack of range-checking allowed private and link-local addresses, including IPv4-mapped IPv6 forms and localhost, to reach the database driver. As a result, authenticated users with connection-test permission could potentially probe internal services accessible from the NocoDB process, such as Redis, cloud metadata endpoints, and internal databases. The vulnerability has been patched in NocoDB version 2026.05.1.
Users can upgrade to NocoDB version 2026.05.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nocodb/nocodb/security/advisories/GHSA-w43h-r5m5-p832 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NocoDB | <= 2026.05.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion