Junglewise Threat Intelligence

CVE-2026-73410: Budibase SSRF via DNS rebinding in REST datasource

CVE-2026-73410 · Severity: low · CVSS 3.1 · Published 2026-07-24

Technologies: @budibase/server (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase's REST datasource integration allows authenticated users to query external APIs and databases. A critical flaw in the DNS rebinding protection means an attacker can bypass IP address validation and redirect requests to internal services (cloud metadata endpoints, databases, internal APIs), potentially stealing cloud credentials or accessing sensitive internal data.

Technical details

The vulnerability is a TOCTOU (time-of-check-time-of-use) / DNS rebinding bypass in the REST datasource integration. Budibase's core fetchWithBlacklist function validates hostnames by resolving them and pinning the connection to a validated IP using a Node.js agent. However, the REST datasource component uses the undici HTTP client, which ignores the Node agent option and performs its own DNS resolution at connection time. An authenticated user (builder or tenant with REST datasource configuration rights) can craft a malicious hostname that resolves to a safe public IP during validation but to an internal IP (e.g., 127.0.0.1, 169.254.169.254, or internal service IPs) at actual connection time. This allows arbitrary HTTP requests to internal-only services with full response exfiltration, including read/write/delete operations. The fix is available in version 3.40.0.

Affected products

  • Budibase Budibase <3.40.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-24: patched: Version 3.40.0

References

Related threats