CVE-2026-82241
Budibase 3.33.4 before 3.41.3: the default SSRF blacklist omits the shared address space 100.64.0.0/10
- Severity
- high
- Affected product
- Budibase
- Affected versions
- Budibase ≥ 3.33.4, < 3.41.3
- Fixed in
- Budibase 3.41.3
- Added to NewScan
- 2026-08-28
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Budibase from its response and reports this CVE when the detected version falls inside the affected range below.
MEASURED 2026-08-28 against vulhub/budibase 3.31.4 (training/cve budibase-idor). Split out of the 3.41.3 row above by its `ge`, the CVE-2026-72859 precedent: @budibase/backend-core's DEFAULT_BLACKLIST was INTRODUCED in 3.33.4 (stated in GHSA-9754-4wm6-3c8r), so on anything older there is no default blacklist for this id to be a hole in and claiming it would be wrong - including on this very test target, which is 3.31.4 and correctly sits below the floor. 100.64.0.0/10 is CGNAT/shared address space and is where cloud and ISP-hosted internal services routinely live, so a datasource URL pointed there reaches them past a blacklist the operator believes covers private ranges. Version-match only, same reason as the row above.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →