Budibase Server versions before 3.41.3 are affected by a server-side request forgery (SSRF) vulnerability in the query import endpoint. The vulnerability arises from a failure to validate user-supplied URLs before fetching content. Attackers can exploit this flaw by submitting arbitrary URLs to make the server retrieve responses from internal services. This includes access to cloud metadata endpoints and other restricted network resources. The vulnerability could allow attackers to map internal infrastructure, steal cloud credentials, or pivot to internal systems. It is tracked as CVE-2026-82246 and has been confirmed by both the NVD and VulnCheck. A fix has been released in Budibase version 3.41.3. Users are strongly advised to upgrade immediately to mitigate the risk.