CVE-2026-45715
📛 CVE Title
(no title)
Description
Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-45715 on 2026-08-01. Shown when MITRE's text differs from the cvelistV5 mirror.
Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access internal services (cloud metadata, databases) by redirecting through an attacker-controlled server. This vulnerability is fixed in 3.38.1.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.7 / 10
- CVSS vector
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N- Effective score
- 7.7 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45715
- Linked Threat
- CVE-2026-45715 — CVE-2026-45715
NVD / KEV / EPSS data refreshed 2026-05-25 00:07 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32603 - Assigner
- GitHub_M
- Published
- May 27, 2026, 5:10:53 PM
- Updated
- May 28, 2026, 2:02:17 PM
- EUVD base score (CVSS 3.1)
-
7.7 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N - EUVD-reported EPSS
- 0.2600
- Vendors
- budibase
- Products
-
budibase (< 3.38.1)
- Aliases
-
GHSA-fgqv-jh4g-pvg2
ENISA description: Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access internal services (cloud metadata, databases) by redirecting through an attacker-controlled server. This vulnerability is fixed in 3.38.1.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/Budibase/budibase/releases/tag/3.38.1 tenable:github.com
- https://github.com/Budibase/budibase/security/advisories/GHSA-fgqv-jh4g-pvg2 tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45715 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45715 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:app.opencve.io
Explore the latest vulnerabilities and security issues in the CVE database
2026-05-26 02:55 UTC -
web:cvedatabase.com
Search and analyze CVE vulnerabilities with instant access to CVSS scores, affected products, and remediation guidance.
2026-05-26 02:55 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-26 02:55 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-05-26 02:55 UTC -
web:windowsreport.com
The newly exposed Windows security flaw, dubbed "YellowKey," has become a major headache for Microsoft. After the exploit details leaked publicly alongside a working proof-of-concept, the company has now rushed out official mitigation guidance while it prepares a permanent fix . The vulnerability reportedly targets BitLocker-protected systems and could allow attackers direct access to ...
2026-05-26 02:55 UTC -
web:www.cisecurity.org
<p>Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...
2026-05-26 02:55 UTC -
web:www.cisonode.com
Microsoft has released an urgent mitigation for a newly disclosed BitLocker bypass vulnerability known as YellowKey, tracked as CVE - 2026 -45585, after proof-of-concept exploit code was publicly released online. The flaw impacts modern versions of Windows 11 and Windows Server 2025 and raises significant concerns for enterprises relying on BitLocker as a primary line of defense for endpoint ...
2026-05-26 02:55 UTC -
web:www.helpnetsecurity.com
Microsoft is working on a fix for CVE - 2026 -45585 (aka "Yellowkey"), a vulnerability that can be used to bypass Windows' BitLocker protection.
2026-05-26 02:55 UTC -
web:www.notebookcheck.net
Microsoft released mitigation steps for YellowKey ( CVE - 2026 -45585), a BitLocker bypass that grants physical attackers access to encrypted Windows drives.
2026-05-26 02:55 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE - 2026 -45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-26 02:55 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.