CVE-2026-67311
Severity CVSS v4.0:
HIGH
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
01/08/2026
Last modified:
01/08/2026
Description
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
6.80
Severity 3.x
MEDIUM



