CVE-2026-63744

SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

22 Jul 2026, 15:45

Type Values Removed Values Added
CPE cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
First Time Surrealdb
Surrealdb surrealdb
References () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h5rg-8p7f-47g2 - () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h5rg-8p7f-47g2 - Vendor Advisory, Mitigation
References () https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-jwks-url-redirect - () https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-jwks-url-redirect - Third Party Advisory

20 Jul 2026, 12:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 12:19

Updated : 2026-07-22 15:45


NVD link : CVE-2026-63744

Mitre link : CVE-2026-63744

CVE.ORG link : CVE-2026-63744


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-918

Server-Side Request Forgery (SSRF)