Junglewise Threat Intelligence

CVE-2026-31818: Budibase SSRF in REST datasource connector

CVE-2026-31818 · Severity: critical · CVSS 9.6 · Published 2026-04-03

Technologies: @budibase/backend-core (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase is a low-code platform used by businesses to build internal applications and connect to various data sources. A security flaw in its REST connector allowed users to bypass intended network restrictions and access sensitive internal systems or data that should have been private. This could lead to unauthorized access to internal databases, cloud metadata services, or other corporate infrastructure.

Technical details

A server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector because the platform's IP blacklist protection was rendered ineffective by default. The protection mechanism relied on the 'BLACKLIST_IPS' environment variable, which was not populated in official deployment configurations; when empty, the validation function would unconditionally permit all requests. An authenticated attacker with permissions to configure REST datasources could exploit this to probe or interact with internal network resources, loopback interfaces, and cloud metadata endpoints (e.g., IMDS). The fix in version 3.33.4 introduces a hardcoded default blacklist covering common private and link-local IPv4/IPv6 ranges and implements a fail-closed approach for DNS resolution and URL parsing errors.

Affected products

  • Budibase Budibase < 3.33.4

Timeline

  • 2026-03-13: patched: Fix merged and version 3.33.4 released.
  • 2026-04-03: disclosed: Public advisory published.

References

Related threats