CVE-2026-31818
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the BLACKLIST_IPS environment variable is not set by default in any of the official deployment configurations. When this variable is empty, the blacklist function unconditionally returns false, allowing all requests through without restriction. This issue has been patched in version 3.33.4.
- Affected products
- Budibase
- Budibase
- < 3.33.4
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 0.4% (31th percentile)
- Weakness
- CWE-918, CWE-1188
- NVD status
- Analyzed
- Published
- 2026-04-03
No indexed exploits for CVE-2026-31818 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-31818 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.