MEDIUM
Budibase
CVE published 2026-04-03
CVE-2026-25043
CVE-2026-25043 is a business logic vulnerability in Budibase’s password reset functionality prior to version 3.23.25. The vulnerability allows an unauthenticated attacker to repeatedly trigger password reset requests for the same email address, resulting in hundreds of password reset emails being sent in a short time window. This enables large-scale email flooding, user harassment, denial of service (DoS) [truncated]