Budibase · @Budibase/Server · CVE-2026-82243
**Name of the Vulnerable Software and Affected Versions**
Budibase Server versions prior to 3.41.3
**Description**
A server-side request forgery (SSRF) issue exists in the datasource verify endpoint. This allows users with builder-level permissions to provide arbitrary URLs that are not properly validated. An attacker can use this to leak internal CouchDB credentials by directing requests to a server under their control, potentially leading to full database access in cloud deployments.
**Recommendations**
Update Budibase Server to version 3.41.3 or later.
Restrict access to the datasource verify endpoint to minimize the risk of exploitation.