SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2025-71398

MEDIUM · CVSS 5.8 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 2.2.2 are vulnerable due to inadequate validation of HTTP redirects in their HTTP functions, allowing authenticated users to circumvent deny-net restrictions. This flaw enables attackers to exploit server-side request forgery (SSRF) by redirecting requests to blocked IP addresses, potentially exposing sensitive internal endpoints. Organizations using SurrealDB should prioritize patching to mitigate the risk of unauthorized access to internal data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71398
Severity
MEDIUM
CVSS
5.8
EPSS
0.23%

Original NVD Description

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.