CVE-2026-54353Disclosure(budibase / budibase)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch budibase budibase systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetch. Since the validated IPs are never pinned to the connection, an attacker-controlled hostname can return a public IP during validation and a private/internal IP during the real connection. This results in a non-blind SSRF primitive against internal services reachable from the Budibase host, including loopback, RFC1918 ranges, and cloud metadata endpoints. This vulnerability is fixed in 3.39.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • budibase

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
budibase

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-26: 2Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-30: 106-2606-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-262
Disclosure2
2026-06-301
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-54353 (CVSS 8.5) - Budibase low-code platform vulnerable to SSRF via DNS rebinding. Authenticated users can bypass blacklist to access internal services. Patch to v3.39.9 immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/dIkQxoCsap

    Post summary

    The tweet announces CVE‑2026‑54353, an SSRF vulnerability in Budibase, and urges users to patch to version 3.39.9 immediately.

    0000070
    55 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54353 Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebind… https://www.cve.org/CVERecord?id=CVE-2026-54353 ----- Traducción: CVE-2026-54353 Bud… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑54353, detailing an SSRF blacklist bypass in Budibase prior to version 3.39.9, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0000035
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54353 Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebind… https://www.cve.org/CVERecord?id=CVE-2026-54353

    Post summary

    CVE-2026-54353 reveals an SSRF bypass in Budibase that allows authenticated automation users to circumvent the DNS blacklist through a DNS rebind technique.

    00000712
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbudibasebudibase---

Explore more