Loading...
Skip to main content

CVE-2025-71398

MEDIUM

SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)

Published April 11, 2025Updated July 19, 2026Source: osv

Summary

SurrealDB offers http functions that can access external network endpoints. A typical, albeit [not recommended ](https://surrealdb.com/docs/surrealdb/reference-guide/security-best-practices#example-deny-all-capabilities-with-some-exceptions) configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, `surreal start --allow-net --deny-net 10.0.0.0/8` will allow all network connections except to the 10.0.0.0/8 block. An authenticated user of SurrealDB can use redirects to bypass this restriction. For example by hosting a server on the public internet which redirects to the IP addresses blocked by the administrator of the SurrealDB server via HTTP 301 or 307 response codes. When sending SurrealDB statements containing the `http::*` functions to the attacker controlled host, the SurrealDB server will follow the redirects to the blocked IP address. Because the statements also return the responses to the attacker, this issue constitutes a full SSRF vulnerability. This issue was discovered and patched during an code audit and penetration test of SurrealDB by cure53, the severity as defined within cure53's preliminary finding is Medium, matched by our CVSS v4 assessment. ### Impact The impact of this vulnerability is circumvention of the `--deny-net` capability and resulting impact on systems external to SurrealDB. The ultimate impact is dependent on the deployment scenario. For example, if the SurrealDB server blocks requests to internal and private IP addresses because they run services which don't require authentication, such as AWS deployments using IMDSv1, the attacker can access these internal endpoints directly, and potentially retrieve or even alter sensitive information and credentials. The circumvention could also be used to redirect traffic to the SurrealDB port, providing a low level of impact to availability. ### Patches A patch has been created that adds an HTTP redirect limit, and checks HTTP redirects against allowed network targets, preventing redirections to disallowed uri's. - Versions 2.0.5, 2.1.5, 2.2.2 and later are not affected by this issue. ### Workarounds The possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability `surreal start --allow-net 10.0.0.0/8 ` or using the equivalent `SURREAL_CAPS_ALLOW_NET` environment variable, where endpoints allowed are fully trusted and are not controlled by regular users. The network access capability can be disabled, using `--deny-net` or the equivalent `SURREAL_CAPS_DENY_NET` environment variable without specifying targets, with impact to SurrealDB functionality. As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. ### References [#5597](https://github.com/surrealdb/surrealdb/pull/5597) [SurrealDB Documentation - Environment Variables](https://surrealdb.com/docs/surrealdb/cli/env) [SurrealDB Documentation - Capabilities](https://surrealdb.com/docs/surrealdb/security/capabilities) [SurrealDB Documentation - Network Access Capability](https://surrealdb.com/docs/surrealdb/security/capabilities#network)

Remediation

Upgrade to the fixed version using your package manager.

Cargo
Update surrealdb to 2.1.5 or later
cargo update -p surrealdb --precise 2.1.5
Cargo
Update surrealdb to 2.2.2 or later
cargo update -p surrealdb --precise 2.2.2
Cargo
Update surrealdb to 2.0.5 or later
cargo update -p surrealdb --precise 2.0.5

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (3)

PackageEcosystemAffectedFixed In
surrealdb
crates.io
All versions2.1.5
surrealdb
crates.io
All versions2.2.2
surrealdb
crates.io
All versions2.0.5

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-918
    Server-Side Request Forgery (SSRF)MITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Confidentiality
Integrity
Availability

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H

Frequently Asked Questions

What is CVE-2025-71398?
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF) This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 9.5/10).
How do I check if my project is affected by CVE-2025-71398?
CVE-2025-71398 affects surrealdb. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-71398 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.5

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-5q9x-554g-9jgg

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies