ZeroHour

CVE-2026-92804

niche

Server-Side Request Forgery in Nango up to 0.70.4

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Nango through version 0.70.4 fails to validate caller-supplied connection configuration values that are interpolated into provider token endpoints and proxy URL templates, resulting in server-side request forgery (CWE-918). An authenticated attacker with low-privileged access can submit crafted configuration values that cause the Nango server to send requests to attacker-chosen internal addresses or cloud metadata endpoints. Successful abuse can leak internal service responses and potentially exfiltrate stored provider credentials such as OAuth tokens. Any deployment running Nango version 0.70.4 or earlier is affected, with self-hosted instances bearing the greatest risk. No public proof-of-concept is known, the flaw is not in CISA KEV, and exploitation has not been observed.

What to do: Upgrade Nango to a release newer than 0.70.4 once a patched version is available, and audit existing connection configurations for unexpected hostnames or URLs. Restrict which API credentials can create or modify connections and apply egress filtering on the Nango server, particularly blocking link-local cloud metadata addresses such as 169.254.169.254. Rotate stored provider credentials if suspicious connection configs or unexplained outbound requests are found.

Affected
Nango (open-source integration/API orchestration server, self-hosted and cloud)all versions through and including 0.70.4
Estimated exposure
nichelikely hundreds to a few thousand self-hosted instances; exact deployment count unknown — No public install counts are available; Nango is an open-source developer integration platform typically adopted by engineering teams as self-hosted instances or via the vendor's cloud, so exposure is plausibly limited to a modest number…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.

Weakness
CWE-918
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.