DNS Rebinding Vulnerability in Budibase Low-Code Platform
CVE-2026-73410
8.5HIGH
What is CVE-2026-73410?
Budibase, an open-source low-code platform, was found to have a vulnerability that allows an attacker to exploit DNS rebinding. This issue arises from the way the platform handled outbound requests prior to version 3.40.0. An improperly handled integration could cause the system to connect to internal addresses after a malicious public address passed validation, giving unauthorized access to the full response and the ability to perform arbitrary REST method calls. The vulnerability has been addressed in version 3.40.0 by enhancing the undici dispatcher to support createPinnedLookup, which secures the validated address against unauthorized requests.
Affected Version(s)
budibase < 3.40.0
