CVE-2025-71390
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-71390",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-71390",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-20T13:38:50.029459Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 5.8,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "LOW",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"vendor": "surrealdb",
"product": "surrealdb",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "2.1.7"
},
{
"status": "affected",
"version": "2.2.0",
"lessThan": "2.2.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.2.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.3.0",
"lessThan": "2.3.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.3.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.0.0-alpha.1",
"versionType": "semver",
"lessThanOrEqual": "3.0.0-alpha.7"
}
],
"packageURL": "pkg:cargo/SurrealDB",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-18T14:17:10.300",
"references": [
{
"url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7",
"tags": [
"Vendor Advisory"
],
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/surrealdb-before-deny-net-bypass-via-dns-resolution",
"tags": [
"Third Party Advisory"
],
"source": "disclosure@vulncheck.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment."
},
{
"lang": "es",
"value": "SurrealDB antes de 2.2.6, 2.3.6 y 2.1.8 (y 3.0.0-alpha.7 y anteriores) no valida los nombres de host resueltos por DNS contra las restricciones de acceso a la red --deny-net en sus funciones http::*. Un usuario autenticado puede invocar http::<fn>(<url>) con un nombre de host que se resuelve en una dirección IP denegada, haciendo que el servidor emita la solicitud de todos modos y devuelva la respuesta. Esto elude los controles de acceso a la red, permitiendo el acceso a puntos finales internos restringidos y potencialmente recuperando o alterando información sensible y credenciales, dependiendo de la implementación."
}
],
"lastModified": "2026-09-29T19:10:00.160",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3A341E9-A010-4E6F-9886-16462B6C2DF2",
"versionEndExcluding": "2.1.8"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3087964-33ED-4300-9DB1-C2F53B05CBFA",
"versionEndExcluding": "2.2.6",
"versionStartIncluding": "2.2.0"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A0D24DD-E841-4FFC-8857-2284EA96A55B",
"versionEndExcluding": "2.3.6",
"versionStartIncluding": "2.3.0"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83C6C6C1-EEC9-439D-AC9D-C0693BFF5E1D"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71C5581F-1FEA-4DA3-9130-C2E75DDF71F1"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3F9C2A9-699D-4C82-B215-837513CC2760"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16E5D9C2-AAA5-4BC1-9BA8-C827336B0CAC"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "280BECEF-32D8-4A57-A083-FD70CAEB98A8"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A589A4EF-EF41-4527-A3C8-68420E361F3D"
},
{
"criteria": "cpe:2.3:a:surrealdb:surrealdb:3.0.0:alpha7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1736B735-8761-4E2F-95D9-D9ACA4789676"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "disclosure@vulncheck.com"
}