High severity7.6NVD Advisory· Published Jul 18, 2026· Updated Aug 19, 2026
CVE-2025-71398
CVE-2025-71398
Description
SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
surrealdbcrates.io | >= 2.2.0, < 2.2.2 | 2.2.2 |
surrealdbcrates.io | >= 2.1.0, < 2.1.5 | 2.1.5 |
surrealdbcrates.io | < 2.0.5 | 2.0.5 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-5q9x-554g-9jggghsaADVISORY
- github.com/surrealdb/surrealdb/security/advisories/GHSA-5q9x-554g-9jggnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-71398ghsaADVISORY
- www.vulncheck.com/advisories/surrealdb-before-ssrf-via-http-redirect-bypassnvdThird Party AdvisoryWEB
- github.com/surrealdb/surrealdb/pull/5597ghsaWEB
News mentions
0No linked articles in our index yet.