CVE-2026-31818Disclosure(budibase / budibase)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch budibase budibase systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the BLACKLIST_IPS environment variable is not set by default in any of the official deployment configurations. When this variable is empty, the blacklist function unconditionally returns false, allowing all requests through without restriction. This issue has been patched in version 3.33.4.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918CWE-1188

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-03); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-03: 3Mentions · 2026-04-04: 2PoC Mentioned / Linked · 2026-04-03: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-03: 3Technical Details · 2026-04-04: 204-0304-04
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-033
Disclosure2Patch1
2026-04-042
Disclosure2
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SSRF vulnerability (CVE-2026-31818) affects `Budibase` via its REST Connector, allowing unauthorized access to internal resources. Review configurations. #SSRF #Budibase #AppSecurity https://www.pulsepatch.io/posts/cve-2026-31818-budibase-ssrf

    Post summary

    The note announces a newly identified SSRF vulnerability in Budibase, provides basic technical details, but does not include a PoC, exploit code, patch, or evidence of active exploitation.

    0000059
    11 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31818 - Critical Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SS... https://www.thehackerwire.com/vulnerability/CVE-2026-31818/ https://t.co/zMdqMYjykx

    Post summary

    The text announces a critical SSRF vulnerability (CVE‑2026‑31818) in Budibase prior to v3.33.4, but does not include PoC, exploit code, or patch information.

    0000059
    164 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31818: CRITICAL] Budibase platform's SSRF vulnerability in REST connector pre-3.33.4 allows unauthorized server access due to IP blacklist configuration oversight. Update to patch security flaw.#cve,CVE-2026-31818,#cybersecurity https://cvefind.com/CVE-2026-31818

    Post summary

    Budibase platform’s pre‑3.33.4 REST connector suffers a critical SSRF flaw; users are urged to update to the latest patch to remediate the vulnerability.

    0000043
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31818 Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connect… https://www.cve.org/CVERecord?id=CVE-2026-31818

    Post summary

    The note alerts to a server‑side request forgery vulnerability in Budibase prior to version 3.33.4, providing technical details but no exploit or remediation information.

    0000046
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31818: Budibase: Server-Side Request Fo... Empty BLACKLIST_IPS var makes Budibase's SSRF protection a complete joke - every internal service becomes reachable via... https://zerodaysignal.com/vulnerability/CVE-2026-31818 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the discovery of a new SSRF vulnerability (CVE‑2026‑31818) in Budibase, noting that an empty blacklist bypasses the protection, and directs readers to a ZerodaySignal article for more details.

    0000059
    197 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more