Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 12:16
Updated : 2026-08-28 18:54
NVD link : CVE-2026-82246
Mitre link : CVE-2026-82246
CVE.ORG link : CVE-2026-82246
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
