CVE-2026-72855: Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST
Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS rebinding attacks. Attackers can configure hostnames that resolve to public addresses during validation but resolve to loopback or private addresses during actual connection, allowing access to blocked internal HTTP services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Budibaseto a version that resolves this vulnerability.Fixed in 3.40.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72855?
The severity of CVE-2026-72855 is high, rated at 8.5.
How do I fix CVE-2026-72855?
To fix CVE-2026-72855, upgrade Budibase to version 3.40.0 or later.
What type of vulnerability is CVE-2026-72855?
CVE-2026-72855 is a server-side request forgery (SSRF) vulnerability.
Who is affected by CVE-2026-72855?
Authenticated builder-level users of Budibase before version 3.40.0 are affected by CVE-2026-72855.
What attack vector is used in CVE-2026-72855?
CVE-2026-72855 exploits DNS rebinding attacks to bypass DNS pinning protections.