HIGH 7.1 NVD
CVE-2026-82246
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources.
References
- https://github.com/Budibase/budibase/security/advisories/GHSA-48x3-9ph2-p9gj
- https://www.vulncheck.com/advisories/budibase-server-before-3.41.3-ssrf-via-query-import
- https://github.com/Budibase/budibase/security/advisories/GHSA-48x3-9ph2-p9gj
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.