top of page
perceptive_background_267k.jpg

Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 21:07:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Supply Chain & Dependencies

CVE-2026-82241 affects Budibase's backend-core package (@budibase/backend-core), which omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST). This omission applies to self-hosted deployments that have not defined a custom BLACKLIST_IPS environment variable. An authenticated user with Builder-level permissions can exploit this by submitting a REST datasource query preview request via POST /api/queries/preview targeting an HTTP(S) service within the 100.64.0.0/10 range. The server will then send a request to that target and return the response to the attacker through the preview flow. No official patch had been released at the time of publication. The recommended remediation is to manually add 100.64.0.0/10 to the DEFAULT_BLACKLIST. This vulnerability poses a risk primarily in self-hosted Budibase environments where internal or carrier-grade NAT services may be reachable within the omitted IP range.

Technical details

Mitigation steps:

Affected products:

Budibase @budibase/backend-core
Budibase @budibase/server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page