Impact
SurrealDB prior to version 3.1.5 contains a server‑side request forgery vulnerability in its JWKS fetcher that follows HTTP redirects without re‑validating the final target against network policy. An attacker with Owner role privileges can configure a JWKS URL pointing to an allowlisted host that redirects to a blocked internal address, allowing the database instance to reach resources it would normally be prevented from accessing. This can compromise the security posture of the database by exposing internal network resources, potentially impacting confidentiality and integrity.
Affected Systems
The vulnerable product is SurrealDB in any release before 3.1.5. Administrators running SurrealDB versions 3.0.x, 3.1.x, or any earlier build are exposed to this risk.
Risk and Exploitability
The CVSS base score is 5.1, indicating a medium severity. The EPSS score is less than 1%, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation. Exploitation requires the attacker to have Owner role access; from that point the attacker can set the JWKS URL to trigger the redirect. Because the redirect target is not validated, the attacker can reach internal networks that should be restricted, making this a bypass of network segmentation controls.
OpenCVE Enrichment