VYPR

Surrealdb

by Surrealdb

cargo: surrealdb

Source repositories

CVEs (58)

  • CVE-2026-63759MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.

  • CVE-2026-63757HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.01

    SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauthenticated attackers can enumerate…

  • CVE-2026-63756HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate…

  • CVE-2026-63754MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can…

  • CVE-2026-63753MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

  • CVE-2026-63752MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing…

  • CVE-2026-63750MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured…

  • CVE-2026-63749MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated…

  • CVE-2026-63747HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.01

    SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.

  • CVE-2026-63745MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by…

  • CVE-2026-63744MedJul 20, 2026
    risk 0.00cvss 4.1epss 0.00

    SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host…

  • CVE-2026-63742MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths. Attackers can execute COUNT queries on indexed fields with field-level SELECT restrictions to confirm or recover restricted field values through repeated…

  • CVE-2026-63741MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing authorization checks in the…

  • CVE-2026-63739HigJul 20, 2026
    risk 0.00cvss 7.7epss 0.00

    SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and…

  • CVE-2026-63737MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression…

  • CVE-2026-63736MedJul 20, 2026
    risk 0.00cvss 4.1epss 0.00

    SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role attacker can point an access method at an allow-listed hostname…

  • CVE-2026-63734MedJul 20, 2026
    risk 0.00cvss 4.9epss 0.00

    SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows authenticated Owner-role users to crash the server by uploading a malformed .surml file to the /ml/import endpoint. Attackers can supply non-numeric…

  • CVE-2026-63309MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field values. Attackers can issue ORDER BY queries on indexed restricted fields to recover the hidden values' sort…

Page 3 of 3