Skip to content

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

High severity GitHub Reviewed Published Jul 22, 2026 in Budibase/budibase • Updated Jul 24, 2026

Package

npm @budibase/server (npm)

Affected versions

<= 3.38.1

Patched versions

None

Description

Impact

A builder-level user can make Budibase issue server-side HTTP requests to loopback or private-network targets by using DNS rebinding against two outbound fetch paths that are still not pinned to the validated DNS answer.

The first path is OpenAPI query import. It validates the supplied hostname with the blacklist and then performs a separate raw fetch. A hostname that resolves to a public address during validation and to 127.0.0.1 during the request is accepted.

The second path is REST datasource/query execution. It calls the fixed fetchWithBlacklist() helper, but provides a custom undici fetchFn that installs a dispatcher. The helper passes a pinned Node agent, but undici uses the dispatcher and resolves the original hostname again at connection time. This defeats the DNS pinning added for the previous outbound fetch advisory.

Impact is authenticated SSRF from the Budibase server process. An attacker with the relevant builder/query privileges can reach loopback or private HTTP services that should be blocked by Budibase's outbound fetch protections, subject to the normal response handling of each feature.

Reproduction

  1. Configure an attacker-controlled hostname so the validation lookup returns a public IP address and the later request lookup returns an internal address such as 127.0.0.1.
  2. Start a loopback canary HTTP service on the Budibase host.
  3. For OpenAPI query import, submit an import URL such as http://rebind.test:<port>/openapi.json through the builder query import endpoints. In a harness matching the current import code, validation resolved rebind.test to 8.8.8.8, the raw fetch then resolved rebind.test to 127.0.0.1, and the loopback canary returned loopback-canary-hit:/openapi.json.
  4. For REST datasource/query execution, configure a REST datasource/query URL using the same rebinding hostname. In a harness matching the current helper plus REST undici custom fetch path, a direct loopback URL was blocked and a pinned Node-agent control did not hit loopback, but the REST undici path re-resolved the hostname to 127.0.0.1 and returned REST-UNDICI-REBIND-CANARY from the loopback service.

Observed OpenAPI import proof:

{
  "outcome": "allowed",
  "body": "loopback-canary-hit:/openapi.json",
  "lookups": [
    {"phase": "guard", "hostname": "rebind.test", "address": "8.8.8.8"},
    {"phase": "fetch", "hostname": "rebind.test", "address": "127.0.0.1"}
  ]
}

Observed REST undici proof:

{
  "directControl": {"outcome": "blocked", "hitsAfter": 0},
  "pinnedNodeFetchControl": {"outcome": "no_loopback_hit", "hitsAfter": 0},
  "undiciBypass": {
    "outcome": "allowed",
    "status": 200,
    "body": "REST-UNDICI-REBIND-CANARY",
    "hitsAfter": 1
  },
  "lookupTrace": [
    {"phase": "guard", "hostname": "rebind.test", "address": "8.8.8.8"},
    {"phase": "fetch", "hostname": "rebind.test", "address": "127.0.0.1"}
  ]
}

Root cause and technical details

The central helper now resolves and validates the target hostname, then passes a pinned Node http.Agent or https.Agent to the request. That protects callers whose HTTP client honors the Node agent option.

OpenAPI query import does not use that helper. In packages/server/src/api/controllers/query/import/index.ts, assertUrlIsSafe() calls blacklist.isBlacklisted(parsed.hostname), but fetchFromUrl() then calls fetch(currentUrl, { redirect: "manual" }). That creates a validate-then-fetch gap where DNS can change between the blacklist lookup and the actual connection.

REST datasource/query execution uses the helper but changes the transport semantics. In packages/server/src/integrations/rest.ts, setDispatcher() creates an undici dispatcher with getDispatcher({ rejectUnauthorized, url: requestUrl }), then the custom fetch function calls fetch(requestUrl, setDispatcher(requestInput, requestUrl)). In packages/backend-core/src/utils/outboundFetch.ts, fetchWithBlacklist() passes the pinned Node agent to fetchFn, but undici fetch uses the supplied dispatcher instead. The actual connection performs a second hostname resolution and can be rebound to a blocked address.

Current affected code is present in latest master and in the latest release tag 3.39.14.

Remediation

Route OpenAPI query import through the pinned outbound fetch helper rather than validating and raw-fetching separately.

Make fetchWithBlacklist() pin the actual connection for every supported transport. For undici callers, provide a dispatcher whose lookup or connect behavior is pinned to the validated IP, or reject custom fetch functions that do not explicitly enforce the pinned address. Add regression coverage for direct loopback blocking, DNS rebinding through OpenAPI import, DNS rebinding through REST undici dispatcher, redirect-to-loopback, IPv4-mapped IPv6, and mixed public/private DNS answers.

References

@mjashanks mjashanks published to Budibase/budibase Jul 22, 2026
Published to the GitHub Advisory Database Jul 24, 2026
Reviewed Jul 24, 2026
Last updated Jul 24, 2026

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

EPSS score

Weaknesses

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Learn more on MITRE.

CVE ID

No known CVE

GHSA ID

GHSA-xg5g-26x8-cvf4

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.