CVE-2026-31818 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Budibase, an open-source low-code platform, in versions prior to 3.33.4. The flaw allows attackers to bypass the platform's intended SSRF protection mechanism because a critical environment variable (BLACKLIST_IPS) is not set by default, rendering the IP blacklist ineffective and permitting unrestricted requests. With a CVSS score of 9.6 (Critical), this vulnerability has a network attack vector, low attack complexity, and requires low privileges, potentially leading to high impact on confidentiality and integrity. While not currently listed in CISA's KEV catalog and lacking public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.33.4CPE matchmatch criteria | cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.