<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 18:47:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-341690</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341690</link>
      <description>EUVD-2026-341690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341690</guid>
    </item>
    <item>
      <title>fkie_cve-2025-71398</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71398</link>
      <description>&lt;p&gt;SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side request forgery to access internal endpoints and retrieve sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-71398</guid>
    </item>
    <item>
      <title>GHSA-5q9x-554g-9jgg — SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5q9x-554g-9jgg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: surrealdb&lt;/p&gt;
&lt;p&gt;SurrealDB offers http functions that can access external network endpoints. A typical, albeit [not recommended ](https://surrealdb.com/docs/surrealdb/reference-guide/security-best-practices#example-deny-all-capabilities-with-some-exceptions) configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, `surreal start --allow-net --deny-net 10.0.0.0/8` will allow all network connections except to the 10.0.0.0/8 block.&lt;/p&gt;
&lt;p&gt;An authenticated user of SurrealDB can use redirects to bypass this restriction. For example by hosting a server on the public internet which redirects to the IP addresses blocked by the administrator of the SurrealDB server via HTTP 301 or 307 response codes.&lt;/p&gt;
&lt;p&gt;When sending SurrealDB statements containing the `http::*` functions to the attacker controlled host, the SurrealDB server will follow the redirects to the blocked IP address. Because the statements also return the responses to the attacker, this issue constitutes a full SSRF vulnerability.&lt;/p&gt;
&lt;p&gt;This issue was discovered and patched during an code audit and penetration test of SurrealDB by cure53, the severity as defined within cure53&amp;#39;s preliminary finding is Medium, matched by our CVSS v4 assessment.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The impact of this vulnerability is circumvention of the `--deny-net` capability and resulting impact on systems external to SurrealDB. The ultimate impact is dependent on the deployment scenario.&lt;/p&gt;
&lt;p&gt;For example, if the SurrealDB serv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: surrealdb&lt;/p&gt;
&lt;p&gt;SurrealDB offers http functions that can access external network endpoints. A typical, albeit [not recommended ](https://surrealdb.com/docs/surrealdb/reference-guide/security-best-practices#example-deny-all-capabilities-with-some-exceptions) configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, `surreal start --allow-net --deny-net 10.0.0.0/8` will allow all network connections except to the 10.0.0.0/8 block.&lt;/p&gt;
&lt;p&gt;An authenticated user of SurrealDB can use redirects to bypass this restriction. For example by hosting a server on the public internet which redirects to the IP addresses blocked by the administrator of the SurrealDB server via HTTP 301 or 307 response codes.&lt;/p&gt;
&lt;p&gt;When sending SurrealDB statements containing the `http::*` functions to the attacker controlled host, the SurrealDB server will follow the redirects to the blocked IP address. Because the statements also return the responses to the attacker, this issue constitutes a full SSRF vulnerability.&lt;/p&gt;
&lt;p&gt;This issue was discovered and patched during an code audit and penetration test of SurrealDB by cure53, the severity as defined within cure53&amp;#39;s preliminary finding is Medium, matched by our CVSS v4 assessment.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The impact of this vulnerability is circumvention of the `--deny-net` capability and resulting impact on systems external to SurrealDB. The ultimate impact is dependent on the deployment scenario.&lt;/p&gt;
&lt;p&gt;For example, if the SurrealDB serv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5q9x-554g-9jgg</guid>
    </item>
  </channel>
</rss>
