CVE Explorer
CVE-2025-71390
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:cargo/SurrealDB","product":"surrealdb","vendor":"surrealdb","versions":[{"lessThanOrEqual":"2.1.7","status":"affected","version":"0","versionType":"semver"},{"lessThan":"2.2.6","status":"affected","version":"2.2.0","versionType":"semver"},{"status":"unaffected","version":"2.2.6","versionType":"semver"},{"lessThan":"2.3.6","status":"affected","version":"2.3.0","versionType":"semver"},{"status":"unaffected","version":"2.3.6","versionType":"semver"},{"lessThanOrEqual":"3.0.0-alpha.7","status":"affected","version":"3.0.0-alpha.1","versionType":"semve…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a36daa6f56d10673de8e650ea6702e95b77d841ed64c62a601b584a1c29ada89 · sha256:87d613be2307194f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":5.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a36daa6f56d10673de8e650ea6702e95b77d841ed64c62a601b584a1c29ada89 · sha256:87d613be2307194f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a36daa6f56d10673de8e650ea6702e95b77d841ed64c62a601b584a1c29ada89 · sha256:87d613be2307194f… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"GitHub Security Advisory (GHSA-m3c3-78fh-w3w7)","tags":["vendor-advisory"],"url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a36daa6f56d10673de8e650ea6702e95b77d841ed64c62a601b584a1c29ada89 · sha256:87d613be2307194f… · /containers/cna/references/0
{"name":"VulnCheck Advisory: SurrealDB before 2.3.6 deny-net Bypass via DNS Resolution","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/surrealdb-before-deny-net-bypass-via-dns-resolution"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a36daa6f56d10673de8e650ea6702e95b77d841ed64c62a601b584a1c29ada89 · sha256:87d613be2307194f… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.