GHSA-xhwm-9486-8rgrMedium

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated...

Published
July 18, 2026
Last Modified
July 18, 2026

🔗 CVE IDs covered (1)

📋 Description

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.

🔗 References (4)