CVE-2026-45719
📛 CVE Title
(no title)
Description
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 6.5 / 10
- CVSS vector
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N- Effective score
- 6.5 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45719
NVD / KEV / EPSS data refreshed 2026-05-25 00:11 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32599 - Assigner
- GitHub_M
- Published
- May 27, 2026, 5:07:20 PM
- Updated
- May 27, 2026, 6:36:23 PM
- EUVD base score (CVSS 3.1)
-
6.5 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N - EUVD-reported EPSS
- 0.2600
- Vendors
- budibase
- Products
-
budibase (< 3.38.1)
- Aliases
-
GHSA-363w-hvwh-w7m6
ENISA description: Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated directly into a CouchDB reduce function definition without validation. Although an internal SCHEMA_MAP object defines the valid calculation types (sum, count, stats), no actual validation is performed against this map before the value is used in string interpolation. A user with Builder permissions can inject arbitrary JavaScript code that will be executed within the CouchDB JavaScript engine when the view is queried. This vulnerability is fixed in 3.38.1.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/Budibase/budibase/releases/tag/3.38.1 tenable:github.com
- https://github.com/Budibase/budibase/security/advisories/GHSA-363w-hvwh-w7m6 tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45719 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45719 tenable:www.cve.org
Remediations (10)
-
web:blog.qualys.com
Oracle released its second quarterly edition of this year's Critical Patch Update. The update received patches for 481 security vulnerabilities.
2026-05-26 03:08 UTC -
web:cyberpress.org
Oracle has released its January 2026 Critical Patch Update (CPU), delivering security patches for 337 vulnerabilities across multiple product families. Published through Oracle's Security Alerts portal, the advisory emphasizes the cumulative nature of these patches and strongly recommends immediate deployment across enterprise environments to ...
2026-05-26 03:08 UTC -
web:nvd.nist.gov
Official websites use .gov A .gov website belongs to an official government organization in the United States.
2026-05-26 03:08 UTC -
web:source.android.com
This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.
2026-05-26 03:08 UTC -
web:support.microsoft.com
Summary Improvements and fixes included in this update How to obtain and install the update How to obtain or download the latest cumulative update package for Linux More information File information Information about protection and security Summary This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories ...
2026-05-26 03:08 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-26 03:08 UTC -
web:www.bugcrowd.com
Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.
2026-05-26 03:08 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-26 03:08 UTC -
web:www.securityweek.com
Oracle on Tuesday announced the release of 481 new security patches as part of its April 2026 Critical Patch Update (CPU). Across the 28 product families that received security updates, more than 300 patches address vulnerabilities that are remotely exploitable without authentication.
2026-05-26 03:08 UTC -
web:www.tanium.com
Find out how unpatched software can compromise your security and discover strategies to mitigate these risks.
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.