Medium severity5.4NVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026
CVE-2026-63758
CVE-2026-63758
Description
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
surrealdbcrates.io | < 3.1.0 | 3.1.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-gcwr-5mrf-fvchghsaADVISORY
- github.com/surrealdb/surrealdb/security/advisories/GHSA-gcwr-5mrf-fvchnvdVendor AdvisoryMitigationWEB
- nvd.nist.gov/vuln/detail/CVE-2026-63758ghsaADVISORY
- www.vulncheck.com/advisories/surrealdb-before-authorization-bypass-via-kill-statementnvdThird Party AdvisoryWEB
- github.com/surrealdb/surrealdb/commit/36f0a41a69b551172c7d1d13b1e8dbbd868e2eadghsaWEB
News mentions
0No linked articles in our index yet.