Nautobot 3.2.6 patches SSO flaws and breaks login flow
Nautobot core v3.2.6 patches a breaking change in SSO login (now HTTP POST instead of GET) due to social-auth-app-django upgrade, and updates social-auth-core to mitigate multiple CVEs. Cable REST API representation standardized.
Why it matters Critical security update and breaking change for Nautobot operators; SSO users must prepare for POST-based authentication flows in deployment pipelines.
Nautobot v3.2.6 (released 2026-09-28) introduces a breaking change as a consequence of upgrading social-auth-app-django to version 6.x: the "Continue with SSO" login action has changed from HTTP GET to HTTP POST. Teams using SSO-based authentication must update their login workflows accordingly.
Security patches include updated social-auth-core to >=5.1.1,<5.2 to mitigate multiple vulnerabilities (GHSA-m6h7-g92h-9p44). Cable representations returned by the cable trace REST API endpoint now use Nautobot's standard serializer fields (display, natural_slug, object_type, url), removing private fields and per-model termination lists. Development dependencies were refreshed (css-loader, postcss, pylint, ruff, mkdocstrings-python).
For Nautobot operators, this release requires attention to SSO configurations before upgrading. The cable API change may affect downstream integrations expecting legacy field structures. Security patches are strongly recommended across all deployment types.
Read the original at github.com ↗