<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Nango (&lt;= 0.70.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nango--0.70.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:57:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nango--0.70.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in Nango via Configuration Interpolation</title><link>https://feed.craftedsignal.io/briefs/2026-09-nango-ssrf/</link><pubDate>Wed, 16 Sep 2026 21:57:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-nango-ssrf/</guid><description>Nango versions through 0.70.4 are vulnerable to Server-Side Request Forgery due to improper validation of user-supplied configuration values in token and proxy URL templates.</description><content:encoded><![CDATA[<p>Nango versions up to and including 0.70.4 contain a Server-Side Request Forgery (SSRF) vulnerability. The issue arises from the application's failure to properly validate caller-supplied connection configuration values before interpolating them into provider token and proxy URL templates. By submitting maliciously crafted configuration inputs, an authenticated attacker can manipulate these templates to force the Nango server to initiate outbound requests to arbitrary destinations. This is particularly critical for cloud-hosted instances, where attackers can direct requests toward internal infrastructure or cloud instance metadata services (e.g., IMDS) to exfiltrate sensitive provider credentials or internal configuration tokens stored within the environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers to perform unauthorized requests on behalf of the Nango server. In cloud environments, this may lead to the compromise of provider credentials, access to internal APIs, or the exfiltration of sensitive metadata. The scope of impact is limited to the network reachability of the Nango instance itself.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching the Nango instance to a version greater than 0.70.4 once an update is available. As a temporary mitigation, audit and restrict the ability of authenticated users to modify connection configurations and implement egress network filtering (e.g., via security groups or firewalls) to prevent the Nango server from reaching cloud metadata endpoints or unauthorized internal IP ranges.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>webserver</category><category>ssrf</category><category>cloud</category></item></channel></rss>