← Back

CVE-2025-71390

nvd nist
Published: Jul 18, 2026Modified: Aug 13, 2026

JSON object

Loading...
5.8
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.

Affected (10)

Products: Surrealdb: Surrealdb
1 product
Surrealdb
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Surrealdb
Before 2.1.8
From 2.2.0 to 2.2.6
From 2.3.0 to 2.3.6
Version 3.0.0 alpha1
Version 3.0.0 alpha2
Version 3.0.0 alpha3
Version 3.0.0 alpha4
Version 3.0.0 alpha5
Version 3.0.0 alpha6
Version 3.0.0 alpha7

References (2)

Timeline

No history available yet.