Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 28, 2026
SurrealDB before 2.2.2 SSRF via HTTP Redirect Bypass
CVE-2025-71398
Description
SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/surrealdb/surrealdb/security/advisories/GHSA-5q9x-554g-9jggmitrevendor-advisory
- www.vulncheck.com/advisories/surrealdb-before-ssrf-via-http-redirect-bypassmitrethird-party-advisory
News mentions
0No linked articles in our index yet.