SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63736

MEDIUM · CVSS 4.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 3.2.0 are vulnerable to a server-side request forgery (SSRF) flaw in the JWKS fetcher, which inadequately validates resolved IP addresses against allow-lists. This allows an attacker with Owner role privileges to exploit the vulnerability by directing requests to internal or loopback addresses, potentially exposing sensitive internal resources. Organizations using SurrealDB should prioritize patching to mitigate the risk of unauthorized access to internal systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63736
Severity
MEDIUM
CVSS
4.1
EPSS
0.23%

Original NVD Description

SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role attacker can point an access method at an allow-listed hostname resolving to private or loopback addresses, causing the server to issue GET requests to internal addresses that would be blocked by direct URL.

Related CVEs

Other vulnerabilities affecting the same vendor(s)