GHSA-xmpv-j7p2-j873 · Severity: low · Ecosystem: pip — Nautobot: Management of users via REST API does not apply configured password validators
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired). This can potentially allow for the creation or modification of users to have passwords that are weak or otherwise do not comply with configured standards. This issue has been patched in versions 2.4.30 and 3.0.10.
Conclusion & alert: CVE-2026-34203 is rated Low Risk (13.3/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.03%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-01 | — | 0.03% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.7 | 3.1 | LOW |
|
1.2 | 1.4 | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
GHSA-xmpv-j7p2-j873 · Severity: low · Ecosystem: pip — Nautobot: Management of users via REST API does not apply configured password validators
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| networktocode | nautobot | < 2.4.30 | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* |
| networktocode | nautobot | >= 3.0.0, < 3.0.10 | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/nautobot/nautobot/commit/589f7caf54124ad76bc9fcbb7bdcaa25627cd598 | Patch |
| https://github.com/nautobot/nautobot/commit/d1ef3135aa02fa07de061e8c085f8cce425fe8c9 | Patch |
| https://github.com/nautobot/nautobot/pull/8778 | Issue Tracking Patch |
| https://github.com/nautobot/nautobot/pull/8779 | Issue Tracking Patch |
| https://github.com/nautobot/nautobot/security/advisories/GHSA-xmpv-j7p2-j873 | Mitigation Patch Vendor Advisory |