Threats Tagged 'ghsa-hfhx-w8p8-4hc7'
View all threats tagged with 'ghsa-hfhx-w8p8-4hc7'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-hfhx-w8p8-4hc7'
Click on any threat for detailed analysis and mitigation recommendations
Server: Budibase: SSRF via bare fetch() in uploadUrl during AI table generation 0 Budibase server versions up to 3.38.1 contain a Server-Side Request Forgery (SSRF) vulnerability in the uploadUrl() function used during AI table generation. The function performs a bare fetch() call on URLs generated by the AI without applying any blacklist or internal IP validation. This allows a builder-level user to cause the server to fetch internal network resources, including cloud metadata endpoints such as 169.254.169.254, potentially exposing sensitive instance credentials and internal services. The vulnerability arises because uploadUrl() lacks the SSRF protections present in other parts of the codebase that use fetchWithBlacklist(). Join the discussion | GCVE Database | 07/24/2026, 21:44:44 UTC Added: 07/25/2026, 23:09:25 UTC |
Showing 1 to 1 of 1 result