CVE-2025-71390

EUVD-2025-210490
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15.94%
Affected Products (NVD)
VendorProductVersion
surrealdbsurrealdb
𝑥
< 2.1.8
surrealdbsurrealdb
2.2.0 ≤
𝑥
< 2.2.6
surrealdbsurrealdb
2.3.0 ≤
𝑥
< 2.3.6
surrealdbsurrealdb
3.0.0:alpha1
surrealdbsurrealdb
3.0.0:alpha2
surrealdbsurrealdb
3.0.0:alpha3
surrealdbsurrealdb
3.0.0:alpha4
surrealdbsurrealdb
3.0.0:alpha5
surrealdbsurrealdb
3.0.0:alpha6
surrealdbsurrealdb
3.0.0:alpha7
𝑥
= Vulnerable software versions