What is CVE-2026-73410?
A vulnerability identified as CVE-2026-73410 in the open-source low-code platform Budibase affects versions prior to 3.40.0, where the REST integration fails to properly utilize a validated address due to a bypass in the fetch dispatcher logic. This can expose the system to potential Server-Side Request Forgery (SSRF) attacks. Users should upgrade to version 3.40.0 or later to mitigate this issue.
Azərbaycanca: Budibase açıq mənbəli low-code platformasında aşkarlanan CVE-2026-73410 zəifliyi REST inteqrasiyası zamanı təsdiqlənmiş ünvanın yoxlanılmaması ilə bağlıdır. Bu, xüsusi konfiqurasiya olunmuş şəbəkə agentinin bypass edilməsinə və potensial Server-Side Request Forgery (SSRF) hücumlarına səbəb ola bilər. 3.40.0 versiyasına qədər təsir edən bu problemi aradan qaldırmaq üçün platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What threat does CVE-2026-73410 pose in the Budibase platform?
The CVE-2026-73410 vulnerability can lead to potential Server-Side Request Forgery (SSRF) attacks due to a bypass in the fetch dispatcher logic, which fails to properly utilize a validated address during REST integration.
Which versions of Budibase are affected by CVE-2026-73410 and how can the issue be resolved?
CVE-2026-73410 affects all versions of Budibase prior to 3.40.0. To mitigate this issue, users should upgrade to version 3.40.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.