SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63744

MEDIUM · CVSS 4.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 3.1.5 are vulnerable to a server-side request forgery (SSRF) flaw in the JWKS fetcher, which improperly handles HTTP redirects without validating their targets against network capabilities. This allows attackers with Owner role to exploit the vulnerability by configuring a JWKS URL that redirects to restricted internal addresses, effectively circumventing network access controls. Organizations using SurrealDB should prioritize patching to mitigate potential unauthorized access to internal resources.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63744
Severity
MEDIUM
CVSS
4.1
EPSS
0.23%

Original NVD Description

SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls.

Related CVEs

Other vulnerabilities affecting the same vendor(s)