Server-Side Request Forgery Vulnerability in Budibase Low-Code Platform
CVE-2026-54353
8.5HIGH
What is CVE-2026-54353?
Budibase, an open-source low-code platform, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that can be exploited by authenticated users with automation permissions. Prior to version 3.39.9, the platform's outbound fetch flow incorrectly manages hostname validation against a blacklist, allowing attackers to perform DNS rebinding. This loophole permits an attacker to execute unauthorized requests to internal services from the Budibase host, potentially exposing sensitive information and resources such as loopback addresses, RFC1918 ranges, and cloud service metadata endpoints.
Affected Version(s)
budibase < 3.39.9
