Junglewise Threat Intelligence

CVE-2026-88403: NocoDB serverRequest Server-Side Request Forgery

CVE-2026-88403 · Severity: medium · CVSS 6.5 · Published 2026-09-21

Vendors: NocoDB.

Executive brief

NocoDB is a low-code database platform that allows users to build custom applications and workflows. This vulnerability allows authenticated users to craft HTTP requests that reach internal network services, bypassing security checks. An attacker could access internal databases, cloud metadata endpoints, or other sensitive services that should only be accessible within the organization's network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the serverRequest function when the SERVER_REQUEST_WHITELIST environment variable is not configured (the default). The checkUrlAgainstWhitelist() function only logs a warning for requests to private IP addresses but does not block them, allowing authenticated attackers to send arbitrary HTTP requests to internal services via the customRequests:send API or similar features.

Affected products

  • NocoDB NocoDB 2.1.21

Timeline

  • 2026-09-07: disclosed
  • 2026-09-21: advisory

References