PT-2026-67291 · Budibase · Budibase

·

CVE-2026-67311

·

Published

2026-08-01

·

Updated

2026-08-03

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.38.1
Description A server-side request forgery (SSRF) issue exists in the REST datasource integration. The system fails to validate HTTP redirects against the IP blacklist, allowing users with the Builder role to configure a REST datasource that points to an external server. This external server can then return a redirect to internal IP addresses, bypassing protection to access internal services and cloud metadata endpoints.
Recommendations Update to version 3.38.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67311
GHSA-86F3-CQPQ-WP9M

Affected Products

Budibase