


Perceptive Security
SOC/SIEM Consultancy

Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (…
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 15:08:13
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
CVE-2026-82241 affects Budibase's backend-core package (@budibase/backend-core), which omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST). This omission allows authenticated users with Builder permissions to send crafted REST datasource query preview requests via POST /api/queries/preview to services within the 100.64.0.0/10 range. The server processes these requests and returns the responses, effectively enabling Server-Side Request Forgery (SSRF). The vulnerability only impacts self-hosted deployments that have not overridden the default blacklist via the BLACKLIST_IPS environment variable. No official patch had been released at the time of publication. The recommended remediation is to manually add 100.64.0.0/10 to the DEFAULT_BLACKLIST configuration.
Technical details
Mitigation steps:
Affected products:
Budibase @budibase/backend-core
Budibase @budibase/server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82241
https://github.com/Budibase/budibase/security/advisories/GHSA-9754-4wm6-3c8r
https://www.vulncheck.com/advisories/budibase-backend-core-ssrf-via-incomplete-default-blacklist
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
