---
id: CVE-2026-72855
title: >-
  Budibase before 3.40.0 contains server-side request forgery vulnerabilities in
  OpenAPI query import and REST query execution that allow authenticated
  builder-level users to bypass DNS pinning protections through DNS rebinding
  attacks
summary: >-
  Budibase before 3.40.0 contains server-side request forgery vulnerabilities in
  OpenAPI query import and REST query execution that allow authenticated
  builder-level users to bypass DNS pinning protections through DNS rebinding
  attacks. At…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-918
vendor: budibase
product: server
affected:
  - server < 3.40.0
published: '2026-08-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:37.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72855'
references:
  - url: >-
      https://github.com/Budibase/budibase/security/advisories/GHSA-xg5g-26x8-cvf4
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/budibase-before-dns-rebinding-ssrf-via-openapi-and-rest
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-14T16:19:37.058077Z'
epss: 0.00375
epssPercentile: 0.29327
ingestedAt: '2026-10-08T16:52:14.716Z'
---

## Overview

Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS rebinding attacks. Attackers can configure hostnames that resolve to public addresses during validation but resolve to loopback or private addresses during actual connection, allowing access to blocked internal HTTP services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
