← Browse

CVE-2025-71398

Medium

Elevated severity or exploit probability.

CVSS base
7.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
EPSS — probability of exploitation (30 days)
0.2%
9.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-918
Published 2026-07-18 · modified 2026-08-19

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityLLow
AvailabilityLLow

Timeline

Description

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.

Affected

surrealdb

References

Official: NVD · CVE.org