PT-2026-94078 · Nango · Nango

·

CVE-2026-92804

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nango versions prior to 0.70.5
Description Authenticated attackers can exploit a lack of validation for caller-supplied connection configuration values that are interpolated into provider token and proxy URL templates. This allows the redirection of server requests to internal addresses or cloud metadata endpoints, which may lead to the exfiltration of provider credentials.
Recommendations Update Nango to version 0.70.5 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92804
GHSA-HGJM-C252-CCXX

Affected Products

Nango