nautobot-ssot
Single Source of Truth for Nautobot
Activity
- Latest release
- 1mo ago
- Total releases
- 72
- Cadence
- ~12 days
- Last 12 months
- 22
Reach
- Stars
- 59
Details
- License
- Apache-2.0
- First release
- Jul 28, 2021
| Version | Released | |
|---|---|---|
4.6.1
patch
| ||
4.6.0
minor
| ||
4.5.2
patch
| ||
4.5.1
patch
| ||
4.5.0
minor
| ||
3.12.5
patch
| ||
4.4.0
minor
| ||
4.3.0
minor
| ||
4.2.2
patch
| ||
3.12.4
patch
| ||
4.2.1
patch
| ||
4.2.0
minor
| ||
3.12.3
patch
| ||
3.12.2
patch
| ||
3.12.1
patch
| ||
3.12.0
minor
| ||
4.1.0
minor
| ||
3.11.1
patch
| ||
4.0.0
major
| ||
3.11.0
minor
| ||
4.0.0a1
pre
| ||
3.10.0
minor
| ||
3.9.4
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.9.3
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.9.2
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.9.1
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.9.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.8.1
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.8.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.7.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.6.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.6.5
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.5.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.4.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.8.1
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.8.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.8.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.8.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.7.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.6.1
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
2.6.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
1.6.4
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.6.3
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.6.2
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
CVE-2025-62607
PYSEC-2026-1690
GHSA-535g-62r7-cx6v
Jul 07, 2026
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
The servicenow config URL is using a generic django View with no authentication. URL: ImpactWhat kind of vulnerability is it? Who is impacted?
An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. PatchesHas the problem been patched? What versions should users upgrade to? We highly recommend upgrading to SSoT v3.10.0 which includes this patch. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Disable the servicenow SSoT integration Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.6.0
+ 38 more Show less
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
2.0.0
2.0.0b1
2.0.0b2
2.0.0rc1
2.0.0rc2
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
3.0.0
3.0.1
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
Fixed in
3.10.0
References
Updated Jul 07, 2026 · Source: OSV.dev |