CVE-2026-63743

SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:port combination, and the redirect is followed because the port information is dropped during redirect policy evaluation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-20 12:19

Updated : 2026-07-22 15:46


NVD link : CVE-2026-63743

Mitre link : CVE-2026-63743

CVE.ORG link : CVE-2026-63743


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-918

Server-Side Request Forgery (SSRF)