# sonatype-2026-005071

@budibase/server - Server-Side Request Forgery (SSRF)

Published Jul 25, 2026

[Advisory · GHSA-hfhx-w8p8-4hc7](https://github.com/advisories/GHSA-hfhx-w8p8-4hc7)

CVSS Score  
Medium  
4.9

### Security Details

**CVE ID**  
sonatype-2026-005071

**CVE Description**  
@budibase/server - Server-Side Request Forgery (SSRF)

**Published**  
Jul 25, 2026

**CVSS Score & Severity**  
4.9 Medium

**CVSS Vector**  
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

**EPSS Score**  
0%

**KEV Status**  
Not in KEV Catalog: No known exploits

**Affected Ecosystems**  
affected

**Source**  
Sonatype

### References

[GitHub · Advisory · GHSA-hfhx-w8p8-4hc7](https://github.com/advisories/GHSA-hfhx-w8p8-4hc7)
