Junglewise Threat Intelligence

CVE-2026-45715: Budibase SSRF bypass via HTTP redirect in REST datasource

CVE-2026-45715 · Severity: high · CVSS 7.7 · Published 2026-05-27

Technologies: Budibase, @budibase/server (npm). Vendors: Budibase, npm.

Executive brief

Budibase, a platform for building business applications, contains a security flaw in its REST data integration. An authorized application builder can trick the system into accessing internal company resources, such as private databases or cloud metadata services, by using a malicious web link that redirects the server. This could lead to the theft of sensitive cloud credentials or unauthorized access to internal business data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the REST datasource integration of Budibase. While the `_req()` method in `packages/server/src/integrations/rest.ts` performs an initial IP blacklist check, it uses the `undici` fetch implementation with default settings that automatically follow HTTP redirects. Because the redirect target is not re-validated against the blacklist, an attacker can provide a URL to a controlled server that issues a 301/302/307 redirect to internal addresses (e.g., 169.254.169.254 or localhost). This allows an authenticated 'Builder' to bypass security controls and access sensitive internal endpoints or cloud metadata. The issue is resolved in version 3.38.1 by ensuring redirects are handled manually and re-checked.

Affected products

  • Budibase Budibase < 3.38.1

Timeline

  • 2026-05-12: disclosed
  • 2026-05-15: advisory
  • 2026-05-15: patched: Version 3.38.1 released

References

Related threats