CVE-2026-63744: SurrealDB before 3.1.5 SSRF via JWKS URL Redirect
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.5 - Compensating control
Ensure network access controls (e.g., firewall/egress allowlists) prevent SurrealDB from reaching blocked internal addresses, since the JWKS fetcher in SurrealDB before 3.1.5 follows HTTP redirects without re-validating redirect targets against network capabilities.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63744?
CVE-2026-63744 has a medium severity score of 5.1.
What type of vulnerability is described in CVE-2026-63744?
CVE-2026-63744 describes a server-side request forgery (SSRF) vulnerability.
How does CVE-2026-63744 exploit JWKS URL requests?
CVE-2026-63744 exploits JWKS URL requests by following HTTP redirects without re-validating redirect targets.
Who is affected by CVE-2026-63744?
Attackers with Owner role in SurrealDB can configure vulnerable JWKS URLs that trigger the vulnerability.
What is the recommended action to mitigate CVE-2026-63744?
Upgrade to SurrealDB version 3.1.5 or later to mitigate CVE-2026-63744.