« Volver al listado

CVE-2025-71390

Estado: AnalizadaMedia (5.8)—

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-71390",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-71390",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-20T13:38:50.029459Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.8,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "HIGH",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "HIGH",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "vendor": "surrealdb",
          "product": "surrealdb",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "2.1.7"
            },
            {
              "status": "affected",
              "version": "2.2.0",
              "lessThan": "2.2.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2.2.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.3.0",
              "lessThan": "2.3.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2.3.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.0.0-alpha.1",
              "versionType": "semver",
              "lessThanOrEqual": "3.0.0-alpha.7"
            }
          ],
          "packageURL": "pkg:cargo/SurrealDB",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-18T14:17:10.300",
  "references": [
    {
      "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://www.vulncheck.com/advisories/surrealdb-before-deny-net-bypass-via-dns-resolution",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment."
    },
    {
      "lang": "es",
      "value": "SurrealDB antes de 2.2.6, 2.3.6 y 2.1.8 (y 3.0.0-alpha.7 y anteriores) no valida los nombres de host resueltos por DNS contra las restricciones de acceso a la red --deny-net en sus funciones http::*. Un usuario autenticado puede invocar http::<fn>(<url>) con un nombre de host que se resuelve en una dirección IP denegada, haciendo que el servidor emita la solicitud de todos modos y devuelva la respuesta. Esto elude los controles de acceso a la red, permitiendo el acceso a puntos finales internos restringidos y potencialmente recuperando o alterando información sensible y credenciales, dependiendo de la implementación."
    }
  ],
  "lastModified": "2026-09-29T19:10:00.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3A341E9-A010-4E6F-9886-16462B6C2DF2",
              "versionEndExcluding": "2.1.8"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3087964-33ED-4300-9DB1-C2F53B05CBFA",
              "versionEndExcluding": "2.2.6",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A0D24DD-E841-4FFC-8857-2284EA96A55B",
              "versionEndExcluding": "2.3.6",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83C6C6C1-EEC9-439D-AC9D-C0693BFF5E1D"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71C5581F-1FEA-4DA3-9130-C2E75DDF71F1"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3F9C2A9-699D-4C82-B215-837513CC2760"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16E5D9C2-AAA5-4BC1-9BA8-C827336B0CAC"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "280BECEF-32D8-4A57-A083-FD70CAEB98A8"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A589A4EF-EF41-4527-A3C8-68420E361F3D"
            },
            {
              "criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1736B735-8761-4E2F-95D9-D9ACA4789676"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosure@vulncheck.com"
}