SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2025-71390

HIGH · CVSS 8.8 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 2.2.6, 2.3.6, and 2.1.8 (as well as 3.0.0-alpha.7 and earlier) lack proper validation of DNS-resolved hostnames against configured network access restrictions, enabling authenticated users to bypass these controls. This vulnerability can lead to unauthorized access to restricted internal endpoints, potentially exposing or compromising sensitive information and credentials. Organizations using affected versions should prioritize remediation to mitigate the risk of data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71390
Severity
HIGH
CVSS
8.8
EPSS
0.25%

Original NVD Description

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.

Related CVEs

Other vulnerabilities affecting the same vendor(s)