A vulnerability marked as problematic has been reported in Budibase up to 3.23.24. This impacts an unknown function of the component Forgot Password Handler. This manipulation causes allocation of resources. This vulnerability is tracked as CVE-2026-25043. The attack is possible to be carried out remotely. No exploit exists. It is suggested to upgrade the affected component.
| Vendor | Product | Versions |
|---|---|---|
| budiba | budibase | < 3.23.25, 3.23.24 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | budibase | cert_advisory | 90% |
Updated description with new details about the vulnerability, changed vendor and product names, added affected version 3.23.24, updated severity to HIGH, and noted that no exploit exists.
Initial creation