Report: Latest: CVE-2026-40346 - NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins
CVE ID :CVE-2026-40346 Published : April 18, 2026, 12:16 a.m. | 1 hour, 15 minutes ago Description :NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...