MEDIUM GitHub
CVE-2025-71390
SurrealDB allows bypass of deny-net flags via DNS resolution
SurrealDB offers http functions that can access external network endpoints. A typical, albeit [not recommended ](https://surrealdb.com/docs/surrealdb/reference-guide/security-best-practices#example-deny-all-capabilities-with-some-exceptions)configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, `surreal start --allow-net --deny-net 10.0.0.0/8` will allow all network connections except to the 10.0.0.0/8 block.
An authenticat
Affected Products
- rust/SurrealDB >= 2.1.0, <= 2.1.7
- rust/SurrealDB >= 2.2.0, <= 2.2.5
- rust/SurrealDB >= 3.0.0-alpha.1, < 3.0.0-alpha.6
- rust/SurrealDB >= 2.3.0, < 2.3.6
References
- https://github.com/advisories/GHSA-m3c3-78fh-w3w7
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7
- https://nvd.nist.gov/vuln/detail/CVE-2025-71390
- https://github.com/surrealdb/surrealdb/pull/6101
This medium severity vulnerability was published on 2026-09-04 via GitHub. Affected: rust/SurrealDB >= 2.1.0, <= 2.1.7, rust/SurrealDB >= 2.2.0, <= 2.2.5, rust/SurrealDB >= 3.0.0-alpha.1, < 3.0.0-alpha.6 and 1 more.
vulnfeed aggregates 10236 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.