Budibase Server versions before 3.41.3 contain a server-side request forgery (SSRF) vulnerability in the query import endpoint. The vulnerability arises from a failure to validate user-supplied URLs before fetching content. Attackers can exploit this flaw by submitting arbitrary URLs to the affected endpoint. Successful exploitation allows retrieval of responses from internal services, including cloud metadata endpoints. This poses a significant risk in cloud-hosted environments where metadata services can expose sensitive credentials and configuration data. The vulnerability also enables access to other restricted network resources not intended to be publicly reachable. Users are advised to upgrade to Budibase Server 3.41.3 or later to remediate the issue. The vulnerability has been assigned CVE-2026-82246 and is documented in both NVD and GitHub Security Advisories.