DNS Rebinding Vulnerability in Budibase Low-Code Platform
CVE-2026-73410

8.5HIGH

Key Information:

Vendor

Budibase

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-73410?

Budibase, an open-source low-code platform, was found to have a vulnerability that allows an attacker to exploit DNS rebinding. This issue arises from the way the platform handled outbound requests prior to version 3.40.0. An improperly handled integration could cause the system to connect to internal addresses after a malicious public address passed validation, giving unauthorized access to the full response and the ability to perform arbitrary REST method calls. The vulnerability has been addressed in version 3.40.0 by enhancing the undici dispatcher to support createPinnedLookup, which secures the validated address against unauthorized requests.

Affected Version(s)

budibase < 3.40.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.