CVE-2026-31818
Budibase, an open‑source low‑code platform, has a critical SSRF vulnerability in its REST datasource connector. The SSRF protection is ineffective because the blacklist variable is not set by default, allowing attackers to force the server to request arbitrary URLs. The issue is fixed in version 3.33.4.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Budibase open‑source low‑code platform, versions prior to 3.33.4.
Real-world impact
An attacker can trick the Budibase server into making requests to any internal or external address, potentially exposing sensitive data or enabling further attacks.
Why this severity
The CVSS score of 9.6 reflects a network‑accessible vulnerability (AV:N) that requires low effort (AC:L) and low privilege (PR:L) to exploit, with no user interaction needed (UI:N). The impact is high on confidentiality and integrity (C:H/I:H) but does not affect availability (A:N).
What to do about it
- 01Upgrade Budibase to version 3.33.4 or later.
NVD-referenced vendor advisory
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/Budibase/budibase/commit/5b…patch
- github.com/Budibase/budibase/pull/1823…issue trackingpatch
- github.com/Budibase/budibase/releases/…productrelease notes
- github.com/Budibase/budibase/security/…exploitmitigationvendor advisory