CVE-2026-92804
nicheServer-Side Request Forgery in Nango up to 0.70.4
Nango through version 0.70.4 fails to validate caller-supplied connection configuration values that are interpolated into provider token endpoints and proxy URL templates, resulting in server-side request forgery (CWE-918). An authenticated attacker with low-privileged access can submit crafted configuration values that cause the Nango server to send requests to attacker-chosen internal addresses or cloud metadata endpoints. Successful abuse can leak internal service responses and potentially exfiltrate stored provider credentials such as OAuth tokens. Any deployment running Nango version 0.70.4 or earlier is affected, with self-hosted instances bearing the greatest risk. No public proof-of-concept is known, the flaw is not in CISA KEV, and exploitation has not been observed.
What to do: Upgrade Nango to a release newer than 0.70.4 once a patched version is available, and audit existing connection configurations for unexpected hostnames or URLs. Restrict which API credentials can create or modify connections and apply egress filtering on the Nango server, particularly blocking link-local cloud metadata addresses such as 169.254.169.254. Rotate stored provider credentials if suspicious connection configs or unexplained outbound requests are found.
| Nango (open-source integration/API orchestration server, self-hosted and cloud) | all versions through and including 0.70.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.
- Weakness
- CWE-918
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.