Junglewise Threat Intelligence

SurrealDB deny-net bypass via DNS resolution

Severity: high · CVSS 8.8 · Published 2026-07-18

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a database server that offers HTTP functions allowing authenticated users to make requests to external endpoints. The product supports network access controls via --deny-net flags to restrict connections to certain IP addresses. However, the server fails to validate DNS-resolved hostnames against these restrictions, allowing authenticated users to bypass network blocks by using hostnames that resolve to denied IP addresses. This could enable attackers to access restricted internal services and retrieve or modify sensitive data.

Technical details

This vulnerability is an authorization bypass (CWE-863) in SurrealDB's network access control mechanism. The root cause is insufficient hostname validation in the http::* function family—while the server checks IP addresses against the --deny-net blocklist, it does not re-validate resolved DNS hostnames after DNS lookup occurs. An authenticated user can exploit this by constructing an http::* call with a hostname that resolves to a blocked IP address. The request proceeds despite the restriction, and the response is returned to the attacker. The vulnerability requires authentication (low-privilege user account) but no user interaction, and is reachable over the network. An attacker can access internal endpoints and services that administrators intended to block, potentially exfiltrating sensitive data or altering configuration. Patches are available in versions 2.1.8, 2.2.6, 2.3.6, and subsequent releases.

Affected products

  • SurrealDB SurrealDB <= 2.1.7, >= 2.2.0 < 2.2.6, >= 2.3.0 < 2.3.6, >= 3.0.0-alpha.1 <= 3.0.0-alpha.7

Timeline

  • 2025-06-26: disclosed: Original advisory GHSA-m3c3-78fh-w3w7 published
  • 2026-07-18: advisory: Duplicate advisory GHSA-vp9r-94xg-q7q8 published
  • 2026-09-04: other: Duplicate advisory GHSA-vp9r-94xg-q7q8 withdrawn

References

Related threats