CVE-2026-46553EPSS p15.0%
CVE-2026-46553CVE-2026-46553
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file's advertised Content-Length or the decoded length of a data: URI, allowing an authenticated user to bypass the configured per-file size limit. This vulnerability is fixed in 2026.04.1.
Scoring
| EPSS | 0.24% probability of exploitation · percentile 15.0% · 2026-08-08T12:02:54Z |
| Last modified | 2026-06-25 |