Budibase SSRF Flaw: Default Config Leaves Open-Source Low-Code Exposed

Budibase SSRF Flaw: Default Config Leaves Open-Source Low-Code Exposed

CVE Notify is flagging a critical Server-Side Request Forgery (SSRF) vulnerability impacting the open-source low-code platform, Budibase. The flaw, identified as CVE-2026-31818, affects versions prior to 3.33.4. According to CVE Notify, the issue stems from Budibase’s REST datasource connector where the built-in SSRF protection mechanism is rendered useless. The problem? The crucial BLACKLIST_IPS environment variable isn’t set by default in official deployment configurations. This oversight means the blacklist function always returns false, allowing unrestricted requests to bypass security checks.

This is a classic case of a security feature being present but not properly enabled out-of-the-box. CVE Notify highlights that when BLACKLIST_IPS is empty, the SSRF protection is effectively nullified. Attackers could potentially leverage this to target internal network resources or external services that the Budibase server has access to, leading to data exfiltration or further network compromise. The good news is that this has been patched in Budibase version 3.33.4.

What This Means For You

  • For organizations using Budibase, immediately verify if the `BLACKLIST_IPS` environment variable is explicitly configured in your deployment, even if you've updated to version 3.33.4, to ensure the SSRF protection is actively enforced.

Related ATT&CK Techniques

πŸ›‘οΈ Detection Rules

1 rule Β· 6 SIEM formats

1 detection rule mapped to MITRE ATT&CK. Free Sigma YAML below.

high T1190 Initial Access

Web Application Exploitation Attempt β€” CVE-2026-31818

Sigma YAML β€” free preview

Source: Shimi's Cyber World Β· License & reuse

Indicators of Compromise

IDTypeIndicator
CVE-2026-31818 SSRF Budibase versions prior to 3.33.4, REST datasource connector, SSRF protection mechanism ineffective due to BLACKLIST_IPS environment variable not being set by default.
CVE-2026-31818 Misconfiguration Budibase versions prior to 3.33.4, BLACKLIST_IPS environment variable not set by default in official deployment configurations, leading to SSRF vulnerability.

Related coverage

Featured

Daily Security Digest β€” 2026-05-22

13 vulnerability disclosures (5 Critical, 8 High) and 14 curated intelligence stories from 6 sources.

daily-digestvulnerabilityCVEhigh-severitycwe-88privilege-escalationcwe-863criticalremote-code-executioncwe-434
/SCW Daily Digest /CRITICAL

WordPress Ditty Plugin: Authorization Bypass Exposes Non-Public Content

CVE-2026-9011 β€” The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...

vulnerabilityCVEhigh-severitycwe-862
/SCW Vulnerability Desk /HIGH /7.5 /⚑ 3 IOCs

CVE-2026-8692 β€” The Vedrixa Forms – User Registration Form, Signup Form &

CVE-2026-8692 β€” The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass...

vulnerabilityCVEmedium-severitycwe-862
/SCW Vulnerability Desk /MEDIUM /4.3 /⚑ 2 IOCs /⚙ 2 Sigma