Executive brief
SurrealDB is a database platform that includes HTTP functions for accessing external network endpoints. Administrators can restrict network access using allowlist and denylist configurations to prevent access to sensitive internal services. This vulnerability allows authenticated database users to circumvent these network restrictions by hosting a public server that redirects HTTP requests to blocked IP addresses, effectively accessing internal systems that should be off-limits. This could expose sensitive data, credentials, or internal services without proper authentication.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) caused by insufficient validation of HTTP redirects in SurrealDB's http functions. SurrealDB deployments typically use --deny-net or --allow-net flags to restrict which network targets the database can access. An authenticated attacker can craft HTTP requests to a publicly controlled server that responds with HTTP 301/307 redirects pointing to internally blocked IP addresses (e.g., 10.0.0.0/8 or AWS IMDSv1). When SurrealDB follows the redirect, it bypasses the network access controls because the initial request passed the allow/deny checks. The attacker receives the response from the blocked internal service, enabling data exfiltration or further attacks. Patches addressing this issue were released in versions 2.0.5, 2.1.5, and 2.2.2, which add redirect limits and validation of redirects against allowed network targets.
Affected products
- SurrealDB SurrealDB < 2.0.5, < 2.1.5, < 2.2.2
Timeline
- 2025-04-10: disclosed: Original advisory GHSA-5q9x-554g-9jgg published
- 2025-04-10: patched: Patches released in versions 2.0.5, 2.1.5, and 2.2.2
- 2026-07-18: other: Duplicate advisory GHSA-xhwm-9486-8rgr published
- 2026-09-04: other: Duplicate advisory withdrawn