{"id":"CVE-2026-44796","aliases":["GHSA-qrpw-gjvh-x5gm","PYSEC-2026-2226"],"url":"https://o3.security/vulnerability/CVE-2026-44796","summary":"Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)","details":"Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the find field in combination with the use_regex flag. This vulnerability is fixed in 2.4.33 and 3.1.2.","published":"2026-05-28T17:00:06.533Z","modified":"2026-07-15T01:49:00.882703451Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00312,"percentile":0.23563,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"nautobot","fixedVersion":"3.1.2"},{"ecosystem":"PyPI","name":"nautobot","fixedVersion":"2.4.33"}],"fix":{"url":"https://github.com/nautobot/nautobot/commit/5a30d0916953afbeedd24a784709e762cc3879cd","label":"nautobot/nautobot@5a30d09"},"references":[{"type":"WEB","url":"https://github.com/nautobot/nautobot/releases/tag/v2.4.33"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/releases/tag/v3.1.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44796.json"},{"type":"ADVISORY","url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-qrpw-gjvh-x5gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44796"},{"type":"FIX","url":"https://github.com/nautobot/nautobot/commit/5a30d0916953afbeedd24a784709e762cc3879cd"},{"type":"FIX","url":"https://github.com/nautobot/nautobot/commit/c2b766966d814a7141f62c7bc90c85fefb7892ee"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:00.882703451Z"}}