<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T12:49:52.795427+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331001</id>
    <title>EUVD-2026-331001</title>
    <updated>2026-10-05T12:49:52.798283+00:00</updated>
    <content>EUVD-2026-331001</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54353</id>
    <title>fkie_cve-2026-54353</title>
    <updated>2026-10-05T12:49:52.798322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetch. Since the validated IPs are never pinned to the connection, an attacker-controlled hostname can return a public IP during validation and a private/internal IP during the real connection. This results in a non-blind SSRF primitive against internal services reachable from the Budibase host, including loopback, RFC1918 ranges, and cloud metadata endpoints. This vulnerability is fixed in 3.39.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gfq7-5x4g-3xhf</id>
    <title>GHSA-gfq7-5x4g-3xhf — @budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation</title>
    <updated>2026-10-05T12:49:52.798376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/backend-core</p>
<p>Summary</p>
<p>Authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding.</p>
<p>The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetch. Since the validated IPs are never pinned to the connection, an attacker-controlled hostname can return a public IP during validation and a private/internal IP during the real connection.</p>
<p>This results in a non-blind SSRF primitive against internal services reachable from the Budibase host, including loopback, RFC1918 ranges, and cloud metadata endpoints.</p>
<p>Details</p>
<p>The issue comes from the outbound fetch validation flow resolving DNS twice:</p>
<p>During blacklist validation
Again during the real socket connection</p>
<p>The first lookup result is discarded after validation, so the second lookup is free to resolve to a different IP.</p>
<p>This creates a classic TOCTOU DNS rebinding issue.</p>
<p>Affected flow in:</p>
<p>packages/backend-core/src/utils/outboundFetch.ts
```
async function throwIfUnsafe(url: string): Promise&lt;void&gt; {
  const parsed = parseUrl(url)</p>
<p>if (await isBlacklisted(parsed.hostname)) {
    throw new Error("URL is blocked or could not be resolved safely.")
  }
}</p>
<p>for (let redirects = 0; redirects &lt;= MAX_REDIRECTS; redirects++) {
  await throwIfUnsafe(nextUrl)</p>
<p>const response = await fetchFn(nextUrl, nextRequest)</p>
<p>// ...
}
```
fetchFn uses plain node-fetch with no custom http.Agent /…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gfq7-5x4g-3xhf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1806</id>
    <title>WID-SEC-W-2026-1806 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-05T12:49:52.798497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1806"/>
  </entry>
</feed>
