GHSA-v42f-v8xc-j435: Budibase: SSRF via DNS rebinding in the REST datasource integration
Summary
Budibase's REST datasource integration has a DNS rebinding vulnerability (TOCTOU, or time-of-check-time-of-use flaw) that defeats IP pinning protection. The system validates a hostname and locks the connection to a safe IP using a Node agent, but the REST path uses undici's fetch instead, which ignores the pinned agent and re-resolves DNS at connection time, allowing an attacker to point the initial validation to a public IP and then rebind to an internal IP to access cloud metadata, databases, or internal services.
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-v42f-v8xc-j435
First tracked: July 24, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 75%