Server-Side Request Forgery Vulnerability in Budibase Low-Code Platform
CVE-2026-54353

8.5HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-54353?

Budibase, an open-source low-code platform, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that can be exploited by authenticated users with automation permissions. Prior to version 3.39.9, the platform's outbound fetch flow incorrectly manages hostname validation against a blacklist, allowing attackers to perform DNS rebinding. This loophole permits an attacker to execute unauthorized requests to internal services from the Budibase host, potentially exposing sensitive information and resources such as loopback addresses, RFC1918 ranges, and cloud service metadata endpoints.

Affected Version(s)

budibase < 3.39.9

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.