CVE-2026-33221 affects Nhost versions prior to 0.12.0, where the storage service's file upload handler trusts client-provided Content-Type headers without server-side validation. This allows an attacker to upload files with arbitrary MIME types, bypassing configured restrictions on storage buckets. Rated with a CVSS 4.0 score of 2.1 (LOW), the vulnerability has a network attack vector but requires high attack complexity, primarily impacting the integrity of stored data. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.0CPE matchmatch criteria | cpe:2.3:a:nhost:storage:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Mar 18, 2026Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Mar 18, 2026Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Mar 18, 2026