CVE-2026-67311: Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Budibaseto a version that resolves this vulnerability.Fixed in 3.38.1 - Compensating control
If you cannot upgrade immediately, restrict network egress from Budibase (especially for REST datasource server-side requests) so it cannot reach internal IP addresses or cloud metadata endpoints.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67311?
CVE-2026-67311 has a medium severity rating of 6.8.
What type of vulnerability is CVE-2026-67311?
CVE-2026-67311 is a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2026-67311?
To fix CVE-2026-67311, update Budibase to version 3.38.1 or later.
What can attackers do with CVE-2026-67311?
Attackers with Builder role can exploit CVE-2026-67311 to bypass the IP blacklist via HTTP redirects.
In which software is CVE-2026-67311 found?
CVE-2026-67311 is found in Budibase versions prior to 3.38.1.