MODERATEcrates.io →
SurrealDB allows bypass of deny-net flags via DNS resolution
SurrealDB allows bypass of deny-net flags via DNS resolution
Affected packages
- SurrealDB
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7
- https://nvd.nist.gov/vuln/detail/CVE-2025-71390
- https://github.com/surrealdb/surrealdb/pull/6101
- https://github.com/surrealdb/surrealdb/pull/6119
- https://github.com/surrealdb/surrealdb/pull/6120
- https://github.com/surrealdb/surrealdb/pull/6121
- https://github.com/surrealdb/surrealdb/commit/4b317d850c7dabaee228144423741097232f7955
- https://github.com/surrealdb/surrealdb/commit/7c574dfa90211923e2ff1b12510c8479f8805b3d
- https://github.com/surrealdb/surrealdb/commit/b80d7d08b043c0e4bc0b7ff8ddb9be0907c0bf59
- https://github.com/surrealdb/surrealdb/commit/d5dc46f1c255ed450b3af025a0bdc165b6ce54a3
- https://github.com/surrealdb/surrealdb
- https://www.vulncheck.com/advisories/surrealdb-before-deny-net-bypass-via-dns-resolution
Structured record: https://osv.dev/vulnerability/GHSA-m3c3-78fh-w3w7
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta