PT-2026-60959 · Surrealdb · Surrealdb

·

CVE-2025-71398

·

Published

2025-04-11

·

Updated

2026-07-21

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 2.2.2
Description Authenticated users can bypass deny-net restrictions in http functions due to a failure to validate HTTP redirects. By hosting a public server that redirects to blocked IP addresses, an attacker can perform server-side request forgery (SSRF)—a technique used to induce the server to make requests to an unintended location—to access internal endpoints and retrieve sensitive information.
Recommendations Update SurrealDB to version 2.2.2 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71398
GHSA-5Q9X-554G-9JGG
GHSA-XHWM-9486-8RGR

Affected Products

Surrealdb