CVE-2026-31818Critical· 9.6▾ MidnightBudibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the BLACKLIST_IPS environment variable is not set by default in any of the official deployment configurations. When this variable is empty, the blacklist function unconditionally returns false, allowing all requests through without restriction. This issue has been patched in version 3.33.4.
budibase < 3.33.4Upgrade past the affected range:
budibase 3.33.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48128MediumBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-35219HighBudibase is an open-source low-code platform
CVE-2026-25044High· 8.8Budibase is an open-source low-code platform
CVE-2026-25043Medium· 5.3Budibase is an open-source low-code platform
GHSA-v42f-v8xc-j435High· 8.5Budibase: SSRF via DNS rebinding in the REST datasource integration