THREAT OPS › Threat News › [GHSA] GHSA-m3c3-78fh-w3w7 (medium) — SurrealDB allows bypass of deny-net flags via DNS resolution
[GHSA] GHSA-m3c3-78fh-w3w7 (medium) — SurrealDB allows bypass of deny-net flags via DNS resolution
GHSA-m3c3-78fh-w3w7 Severity: medium CVE: CVE-2025-71390
SurrealDB allows bypass of deny-net flags via DNS resolution
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start Surreal
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2025-71390cve
- https://surrealdb.com/docs/surrealdb/reference-guide/security-best-practices#example-deny-all-capabilities-with-some-exceptions)configurationurl
- 10.0.0.0/8cidr
Original source: https://github.com/advisories/GHSA-m3c3-78fh-w3w7