PT-2026-30188 · Budibase · Budibase

Moonster8282

·

Published

2026-04-03

·

Updated

2026-04-04

·

CVE-2026-31818

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
**Name of the Vulnerable Software and Affected Versions Budibase versions prior to 3.33.4
**Description Budibase, an open-source low-code platform, contains a server-side request forgery (SSRF) vulnerability in its REST datasource connector. The platform's SSRF protection is ineffective because the BLACKLIST IPS environment variable is not set by default in official deployment configurations. When this variable is empty, the blacklist function always returns false, allowing unrestricted requests. This allows access to internal services.
**Recommendations Update Budibase to version 3.33.4 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-31818
GHSA-7R9J-R86Q-7G45

Affected Products

Budibase