Server-Side Request Forgery Vulnerability in Nango by NangoHQ
CVE-2026-92804
7.1HIGH
What is CVE-2026-92804?
Nango versions up to 0.70.4 have a vulnerability that allows authenticated attackers to exploit improperly validated connection configuration values. This flaw can enable attackers to manipulate server requests, redirecting them to internal addresses or cloud metadata endpoints. By doing so, they could potentially extract sensitive credentials from the provider, posing significant security risks.
Affected Version(s)
Nango 0 <= 0.70.4
