CVE-2026-46553: NocoDB: Attachment Size Limit Bypass via Upload-by-URL
The upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file’s advertised Content-Length or the decoded length of a data: URI, allowing an authenticated user to bypass the configured per-file size limit.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-46553 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →