Vulnerability Description
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Surrealdb | Surrealdb | < 2.1.8 |
Related Weaknesses (CWE)
References
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7Vendor Advisory
- https://www.vulncheck.com/advisories/surrealdb-before-deny-net-bypass-via-dns-reThird Party Advisory
FAQ
What is CVE-2025-71390?
CVE-2025-71390 is a vulnerability with a CVSS score of 8.8 (HIGH). SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authentica...
How severe is CVE-2025-71390?
CVE-2025-71390 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71390?
Check the references section above for vendor advisories and patch information. Affected products include: Surrealdb Surrealdb.