@budibase/backend-core vulnerabilities
CVEs whose affected-version data names the @budibase/backend-core package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54353High· 8.5@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
▾ Twilightbudibase · @budibase/backend-coreEPSS 0.21%via GHSA
CVE-2026-48147Medium· 6.5Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
▾ Sunlitbudibase · @budibase/backend-coreEPSS 0.11%via GHSA