SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.
References
| Link | Resource |
|---|---|
| https://github.com/surrealdb/surrealdb/security/advisories/GHSA-5q9x-554g-9jgg | Vendor Advisory |
| https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-http-redirect-bypass | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-18 14:17
Updated : 2026-08-19 17:49
NVD link : CVE-2025-71398
Mitre link : CVE-2025-71398
CVE.ORG link : CVE-2025-71398
JSON object : View
Products Affected
surrealdb
- surrealdb
CWE
CWE-918
Server-Side Request Forgery (SSRF)
