Vulnerability Description
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted network resources.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Budibase/budibase/security/advisories/GHSA-48x3-9ph2-p9gj
- https://www.vulncheck.com/advisories/budibase-server-before-3.41.3-ssrf-via-quer
- https://github.com/Budibase/budibase/security/advisories/GHSA-48x3-9ph2-p9gj
FAQ
What is CVE-2026-82246?
CVE-2026-82246 is a vulnerability with a CVSS score of 7.1 (HIGH). Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit ...
How severe is CVE-2026-82246?
CVE-2026-82246 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82246?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.