CVE-2026-63736
EUVD-2026-4590720.07.2026, 12:19
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role attacker can point an access method at an allow-listed hostname resolving to private or loopback addresses, causing the server to issue GET requests to internal addresses that would be blocked by direct URL.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| surrealdb | surrealdb | 𝑥 < 3.2.0 |
𝑥
= Vulnerable software versions