# sonatype-2026-005075

@budibase/server - Server-Side Request Forgery (SSRF)

Published Jul 25, 2026

[Advisory · GHSA-xg5g-26x8-cvf4](https://github.com/advisories/GHSA-xg5g-26x8-cvf4)

## CVSS Score
High

**8.5**

## Security Details
### Components Impacted

**Sonatype Research**

### sonatype-2026-005075 Security Details

CVE ID: **sonatype-2026-005075**  
CWE: **N/A**  
CVE Description: @budibase/server - Server-Side Request Forgery (SSRF)  
Published: **Jul 25, 2026**

### CVSS Score & Severity
**8.5 High**

### CVSS Vector
**CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N**

### EPSS Score
**0%**

### Malware
**malware**

### KEV Status
Not in KEV Catalog: **No known exploits**

### Affected Ecosystems
**affected**

### Source
**Sonatype**

### References
[GitHub · Advisory · GHSA-xg5g-26x8-cvf4](https://github.com/advisories/GHSA-xg5g-26x8-cvf4 "https://github.com/advisories/GHSA-xg5g-26x8-cvf4")
