Every story tagged Budibase, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
CVE-2026-67311 is a high-severity SSRF vulnerability (CVSS 8.2) in Budibase versions before 3.38.1 that allows authenticated Builder-role users to bypass IP blacklist protections and access internal services and cloud metadata endpoints through malicious HTTP redirects. This vulnerability poses significant risk to organizations using Budibase for data integration, potentially enabling attackers with platform access to exfiltrate sensitive infrastructure information and compromise internal systems. IT organizations must immediately assess their Budibase deployments and implement strict access controls on Builder role assignments while planning urgent upgrades to version 3.38.1 or later.
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services.