{"id":"CVE-2025-71398","title":"SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses","summary":"SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied n…","severity":"none","cwe":["CWE-918"],"published":"2026-07-18","updated":"2026-07-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-71398","references":[{"url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-5q9x-554g-9jgg","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-http-redirect-bypass","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-07-19T05:29:21.322Z","epss":0.00328,"epssPercentile":0.23265,"slug":"CVE-2025-71398","body":"## Overview\n\nSurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}