SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:port combination, and the redirect is followed because the port information is dropped during redirect policy evaluation.
References
| Link | Resource |
|---|---|
| https://github.com/surrealdb/surrealdb/security/advisories/GHSA-97vg-427p-8hx5 | Vendor Advisory Mitigation |
| https://www.vulncheck.com/advisories/surrealdb-before-port-specific-deny-rule-bypass-via-http-redirect | Third Party Advisory |
Configurations
History
22 Jul 2026, 15:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-97vg-427p-8hx5 - Vendor Advisory, Mitigation | |
| References | () https://www.vulncheck.com/advisories/surrealdb-before-port-specific-deny-rule-bypass-via-http-redirect - Third Party Advisory | |
| CPE | cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:* | |
| First Time |
Surrealdb
Surrealdb surrealdb |
20 Jul 2026, 12:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-20 12:19
Updated : 2026-07-22 15:46
NVD link : CVE-2026-63743
Mitre link : CVE-2026-63743
CVE.ORG link : CVE-2026-63743
JSON object : View
Products Affected
surrealdb
- surrealdb
CWE
CWE-918
Server-Side Request Forgery (SSRF)
