HTTP Redirect Handling Vulnerability in SurrealDB by SurrealDB
CVE-2026-63743
5.3MEDIUM
What is CVE-2026-63743?
SurrealDB prior to version 3.1.0 suffers from a vulnerability in its HTTP redirect handling, allowing authenticated users to skip port-scoped --deny-net rules. This occurs when attackers exploit an HTTP redirect from an authorized hostname to an unauthorized host:port, leading to a bypass of the intended security policies as the port information is disregarded during redirect processing.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
