<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:11:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322418</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322418</link>
      <description>EUVD-2026-322418</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322418</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48146</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48146</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was not applied to the OAuth2 token endpoint. A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB, cloud metadata) to exfiltrate sensitive data. This vulnerability is fixed in 3.39.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was not applied to the OAuth2 token endpoint. A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB, cloud metadata) to exfiltrate sensitive data. This vulnerability is fixed in 3.39.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48146</guid>
    </item>
    <item>
      <title>GHSA-g6qx-g4pr-92v7 — Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g6qx-g4pr-92v7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The OAuth2 token fetch function in `packages/server/src/sdk/workspace/oauth2/utils.ts` (line 59) uses raw `fetch(config.url)` with **no SSRF protection**. The safe wrapper `fetchWithBlacklist()` exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was **not applied** to the OAuth2 token endpoint.&lt;/p&gt;
&lt;p&gt;A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB, cloud metadata) to exfiltrate sensitive data.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable code — `packages/server/src/sdk/workspace/oauth2/utils.ts:59`:**&lt;/p&gt;
&lt;p&gt;```typescript
async function fetchToken(config: OAuth2Config): Promise&amp;lt;TokenResponse&amp;gt; {
  // ...
  const response = await fetch(config.url, fetchConfig)  // NO blacklist check!
  // ...
}
```&lt;/p&gt;
&lt;p&gt;**Safe wrapper used everywhere else — `packages/backend-core/src/utils/outboundFetch.ts`:**&lt;/p&gt;
&lt;p&gt;```typescript
export async function fetchWithBlacklist(url: string, opts?: RequestInit) {
  await blacklist.isBlacklisted(url)  // Checks against internal IPs
  const response = await fetch(url, { ...opts, redirect: &amp;#34;manual&amp;#34; })
  // Re-checks every redirect target
}
```&lt;/p&gt;
&lt;p&gt;**Where `fetchWithBlacklist` IS used (consistency gap proof):**
- `automations/steps/discord.ts` — Discord webhook
- `automations/steps/slack.ts` — Slack webhook
- `automations/steps/make.ts` — Make.com integration
- `automations/steps/n8n.ts` — n8n integration
- `automations/steps/zapier.ts` — Zapier integration
- `automati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The OAuth2 token fetch function in `packages/server/src/sdk/workspace/oauth2/utils.ts` (line 59) uses raw `fetch(config.url)` with **no SSRF protection**. The safe wrapper `fetchWithBlacklist()` exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was **not applied** to the OAuth2 token endpoint.&lt;/p&gt;
&lt;p&gt;A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB, cloud metadata) to exfiltrate sensitive data.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable code — `packages/server/src/sdk/workspace/oauth2/utils.ts:59`:**&lt;/p&gt;
&lt;p&gt;```typescript
async function fetchToken(config: OAuth2Config): Promise&amp;lt;TokenResponse&amp;gt; {
  // ...
  const response = await fetch(config.url, fetchConfig)  // NO blacklist check!
  // ...
}
```&lt;/p&gt;
&lt;p&gt;**Safe wrapper used everywhere else — `packages/backend-core/src/utils/outboundFetch.ts`:**&lt;/p&gt;
&lt;p&gt;```typescript
export async function fetchWithBlacklist(url: string, opts?: RequestInit) {
  await blacklist.isBlacklisted(url)  // Checks against internal IPs
  const response = await fetch(url, { ...opts, redirect: &amp;#34;manual&amp;#34; })
  // Re-checks every redirect target
}
```&lt;/p&gt;
&lt;p&gt;**Where `fetchWithBlacklist` IS used (consistency gap proof):**
- `automations/steps/discord.ts` — Discord webhook
- `automations/steps/slack.ts` — Slack webhook
- `automations/steps/make.ts` — Make.com integration
- `automations/steps/n8n.ts` — n8n integration
- `automations/steps/zapier.ts` — Zapier integration
- `automati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g6qx-g4pr-92v7</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1629 — Budibase: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</guid>
    </item>
  </channel>
</rss>
