Executive brief
Budibase is a low-code application platform that allows builders to configure data sources and import external APIs. A builder-level user can exploit DNS rebinding to bypass network security controls and make the Budibase server perform HTTP requests to internal services (like loopback addresses) that should be blocked. This allows attackers with builder privileges to access private systems, potentially extracting sensitive data or compromising internal infrastructure.
Technical details
The vulnerability is a DNS rebinding SSRF (CWE-918) affecting two code paths: OpenAPI query import and REST datasource/query execution. In OpenAPI import (packages/server/src/api/controllers/query/import/index.ts), the code validates a hostname against a blacklist but then performs a separate raw fetch, creating a TOCTOU gap where DNS can resolve to a different address between validation and connection. In REST execution (packages/server/src/integrations/rest.ts), the helper passes a pinned Node agent but the custom undici dispatcher re-resolves the hostname at connection time, defeating DNS pinning protections. An authenticated builder can craft a rebinding hostname that resolves to a public address during validation and to 127.0.0.1 during the actual request. The attack requires builder-level authentication and network reachability to a controlled DNS server but no user interaction. Affected versions prior to 3.40.0 allow reaching loopback and private HTTP services.
Affected products
- Budibase Budibase <3.40.0
Timeline
- 2026-07-24: disclosed
- 2026-07-24: patched: version 3.40.0 released