SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63743

MEDIUM · CVSS 6.4 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 3.1.0 are vulnerable to a capability bypass in HTTP redirect handling, enabling authenticated users to bypass port-scoped --deny-net rules. This flaw allows attackers to exploit HTTP redirects from permitted hostnames to restricted host:port combinations, potentially leading to unauthorized access to sensitive resources. Organizations using SurrealDB should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63743
Severity
MEDIUM
CVSS
6.4
EPSS
0.18%

Original NVD Description

SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:port combination, and the redirect is followed because the port information is dropped during redirect policy evaluation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)