CVE-2026-67311
Received Received - Intake

Server-Side Request Forgery in Budibase Before 3.38.1

Vulnerability report for CVE-2026-67311, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
budibase budibase to 3.38.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Budibase before version 3.38.1 has a server-side request forgery (SSRF) vulnerability in its REST datasource integration. The flaw occurs because the system fails to validate HTTP redirects against an IP blacklist. Attackers with a Builder role can exploit this by setting up a REST datasource that points to an external server, which then redirects requests to internal IP addresses. This bypasses the blacklist protection, allowing access to cloud metadata endpoints and internal services.

Detection Guidance

Check Budibase server logs for unusual REST datasource requests or redirects to internal IP addresses. Monitor network traffic for outbound connections to internal IPs from Budibase processes. Review datasource configurations for external endpoints that may redirect to internal services.

Impact Analysis

If you are a Budibase user with Builder role, an attacker could exploit this to access internal services or cloud metadata, potentially leading to data breaches or unauthorized access to sensitive information. For users without Builder role, the risk is lower but still exists if an attacker gains elevated privileges.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations using affected Budibase versions may face legal and regulatory penalties if a breach occurs due to this flaw.

Mitigation Strategies

Upgrade Budibase to version 3.38.1 or later. Disable or restrict REST datasource configurations with external endpoints. Implement strict IP whitelisting for internal services. Monitor and block suspicious redirect patterns in network traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67311. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart