{"id":"CVE-2026-44798","aliases":["GHSA-p3hx-pwf3-j8wr","PYSEC-2026-2228"],"url":"https://o3.security/vulnerability/CVE-2026-44798","summary":"Nautobot: GitRepository.current_head field should not be writable through REST API","details":"### Impact\n\nA user with access to add/change a GitRepository record could use the REST API to directly set the `current_head` field on the record, which was not intended to be user-editable. Doing so could cause Nautobot's local clone(s) of the relevant repository to checkout a commit other than the latest commit on the specified `branch` (resulting in misleading state), or potentially to be unable to make use of the repository at all (until manually remediated) due to the `current_head` pointing to a nonexistent commit hash or malformed value.\n\n### Patches\n\nThe issue has been remediated in Nautobot v2.4.33 and 3.1.2.\n\n\n### Workarounds\n\nNote that many of the same end-result symptoms could be caused by a user with the same level of access simply changing the `branch` or `remote_url` of a GitRepository rather than crafting the `current_head`. Administrators are encouraged to carefully review which users are granted permissions to create and modify GitRepository records.\n\n\n### References\n\n- 2.4.33 (<a href=\"https://github.com/nautobot/nautobot/commit/9deddfc91ad9260ad17b5e20084e9e2d15be3609\">patch</a>)\n- 3.1.2 (<a href=\"https://github.com/nautobot/nautobot/commit/c46f97040b2bde4320be36b23577f19a8bcbd8c3\">patch</a>)","published":"2026-05-28T16:57:45.734Z","modified":"2026-08-12T03:51:09.917194447Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"},"epss":{"score":0.00277,"percentile":0.19584,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"nautobot","fixedVersion":"3.1.2"},{"ecosystem":"PyPI","name":"nautobot","fixedVersion":"2.4.33"}],"fix":{"url":"https://github.com/nautobot/nautobot/commit/9deddfc91ad9260ad17b5e20084e9e2d15be3609","label":"nautobot/nautobot@9deddfc"},"references":[{"type":"WEB","url":"https://github.com/nautobot/nautobot/releases/tag/v2.4.33"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/releases/tag/v3.1.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44798.json"},{"type":"ADVISORY","url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-p3hx-pwf3-j8wr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44798"},{"type":"FIX","url":"https://github.com/nautobot/nautobot/commit/9deddfc91ad9260ad17b5e20084e9e2d15be3609"},{"type":"FIX","url":"https://github.com/nautobot/nautobot/commit/c46f97040b2bde4320be36b23577f19a8bcbd8c3"},{"type":"PACKAGE","url":"https://github.com/nautobot/nautobot"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.917194447Z"}}