Executive brief
SurrealDB is a database server that offers HTTP functions allowing authenticated users to make requests to external endpoints. The product supports network access controls via --deny-net flags to restrict connections to certain IP addresses. However, the server fails to validate DNS-resolved hostnames against these restrictions, allowing authenticated users to bypass network blocks by using hostnames that resolve to denied IP addresses. This could enable attackers to access restricted internal services and retrieve or modify sensitive data.
Technical details
This vulnerability is an authorization bypass (CWE-863) in SurrealDB's network access control mechanism. The root cause is insufficient hostname validation in the http::* function family—while the server checks IP addresses against the --deny-net blocklist, it does not re-validate resolved DNS hostnames after DNS lookup occurs. An authenticated user can exploit this by constructing an http::* call with a hostname that resolves to a blocked IP address. The request proceeds despite the restriction, and the response is returned to the attacker. The vulnerability requires authentication (low-privilege user account) but no user interaction, and is reachable over the network. An attacker can access internal endpoints and services that administrators intended to block, potentially exfiltrating sensitive data or altering configuration. Patches are available in versions 2.1.8, 2.2.6, 2.3.6, and subsequent releases.
Affected products
- SurrealDB SurrealDB <= 2.1.7, >= 2.2.0 < 2.2.6, >= 2.3.0 < 2.3.6, >= 3.0.0-alpha.1 <= 3.0.0-alpha.7
Timeline
- 2025-06-26: disclosed: Original advisory GHSA-m3c3-78fh-w3w7 published
- 2026-07-18: advisory: Duplicate advisory GHSA-vp9r-94xg-q7q8 published
- 2026-09-04: other: Duplicate advisory GHSA-vp9r-94xg-q7q8 withdrawn