← All CVEs NewScan detects
high

CVE-2026-82241

Budibase 3.33.4 before 3.41.3: the default SSRF blacklist omits the shared address space 100.64.0.0/10

Severity
high
Affected product
Budibase
Affected versions
Budibase ≥ 3.33.4, < 3.41.3
Fixed in
Budibase 3.41.3
Added to NewScan
2026-08-28
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Budibase from its response and reports this CVE when the detected version falls inside the affected range below.

MEASURED 2026-08-28 against vulhub/budibase 3.31.4 (training/cve budibase-idor). Split out of the 3.41.3 row above by its `ge`, the CVE-2026-72859 precedent: @budibase/backend-core's DEFAULT_BLACKLIST was INTRODUCED in 3.33.4 (stated in GHSA-9754-4wm6-3c8r), so on anything older there is no default blacklist for this id to be a hole in and claiming it would be wrong - including on this very test target, which is 3.31.4 and correctly sits below the floor. 100.64.0.0/10 is CGNAT/shared address space and is where cloud and ISP-hosted internal services routinely live, so a datasource URL pointed there reaches them past a blacklist the operator believes covers private ranges. Version-match only, same reason as the row above.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →