<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T15:14:51.644682+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341478</id>
    <title>EUVD-2026-341478</title>
    <updated>2026-10-07T15:14:51.692839+00:00</updated>
    <content>EUVD-2026-341478</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63743</id>
    <title>fkie_cve-2026-63743</title>
    <updated>2026-10-07T15:14:51.692879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:port combination, and the redirect is followed because the port information is dropped during redirect policy evaluation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-97vg-427p-8hx5</id>
    <title>GHSA-97vg-427p-8hx5 — SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect</title>
    <updated>2026-10-07T15:14:51.692914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: surrealdb</p>
<p>SurrealDB offers `http::*` functions that can access external network endpoints, with the `--allow-net` and `--deny-net` capabilities used to restrict the set of network targets that can be reached. An authenticated user of SurrealDB can bypass a port-scoped `--deny-net &lt;host&gt;:&lt;port&gt;` rule by chaining an HTTP redirect: the initial request goes to an `--allow-net`-permitted hostname, the response's `3xx Location` header points at the denied `host:port`, and the redirect is followed even though the destination was explicitly denied.</p>
<p>The root cause is in the redirect policy applied to outbound HTTP requests (`surrealdb/core/src/fnc/util/http/mod.rs`): the `NetTarget` for the redirect destination is built from `url.host_str()` alone and `url.port()` is dropped. The capability matcher (`surrealdb/core/src/dbs/capabilities.rs:259-264`) refuses to match a port-bearing rule against a port-stripped target (`Self::Host(host, Some(port)) =&gt; match tgt { _ =&gt; false }`), so the operator's port-scoped deny rule silently does not fire on the redirect target.</p>
<p>### Impact</p>
<p>The impact of this vulnerability is circumvention of the `--deny-net` capability when the operator has scoped deny rules by port, and the resulting impact on systems external to SurrealDB. The ultimate impact is dependent on the deployment scenario.</p>
<p>For example, if a SurrealDB operator uses `--deny-net &lt;host&gt;:&lt;port&gt;` to block specific internal services (such as a local Redis at `192.168.1.1:6379` or an unauthenticated clo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-97vg-427p-8hx5"/>
  </entry>
</feed>
