CVE-2025-71398: SurrealDB before 2.2.2 SSRF via HTTP Redirect Bypass
SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71398?
CVE-2025-71398 has a medium severity rating of 5.8 according to the CVSS score.
What type of vulnerability is CVE-2025-71398?
CVE-2025-71398 is a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2025-71398?
To mitigate CVE-2025-71398, upgrade SurrealDB to version 2.2.2 or later.
What are the risks associated with CVE-2025-71398?
CVE-2025-71398 allows authenticated users to bypass network restrictions, potentially accessing sensitive resources.
What software is affected by CVE-2025-71398?
CVE-2025-71398 affects versions of SurrealDB prior to 2.2.2.