VYPR

Vendor CVEs

Surrealdb

All CVEs

58 total · sorted by risk
  • CVE-2025-71390HigJul 18, 2026
    risk 0.50cvss 8.8epss 0.00

    SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::() with a hostname that resolves to a denied…

  • CVE-2024-58362HigJul 18, 2026
    risk 0.50cvss 8.8epss 0.00

    SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is…

  • CVE-2023-54366HigJul 18, 2026
    risk 0.50cvss 8.8epss 0.00

    SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform…

  • CVE-2024-58366HigJul 18, 2026
    risk 0.48cvss 8.5epss 0.00

    SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB…

  • CVE-2025-71392HigJul 18, 2026
    risk 0.45cvss 8.0epss 0.00

    SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL.…

  • CVE-2024-58368HigJul 18, 2026
    risk 0.42cvss 7.5epss 0.00

    SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the…

  • CVE-2025-71395HigJul 18, 2026
    risk 0.39cvss epss 0.00

    SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to exhaust server memory through unbounded…

  • CVE-2025-71397MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to define custom database functions via DEFINE FUNCTION using nested FOR loops. Although a single loop's…

  • CVE-2025-71396MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all). An authenticated attacker can…

  • CVE-2025-71393MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger…

  • CVE-2025-71391MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes…

  • CVE-2024-58370MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack overflow and crash the server.

  • CVE-2024-58369MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of…

  • CVE-2024-58367MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploit SELECT VALUE operations, field aliasing,…

  • CVE-2024-58365MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server.

  • CVE-2024-58364MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the…

  • CVE-2024-58361MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause…

  • CVE-2024-58359MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server.

  • CVE-2024-58357MedJul 18, 2026
    risk 0.35cvss 6.5epss 0.00

    SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause…

  • CVE-2024-58363MedJul 18, 2026
    risk 0.34cvss 6.3epss 0.00

    SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical…

  • CVE-2024-58356MedJul 18, 2026
    risk 0.34cvss 6.3epss 0.00

    SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does…

  • CVE-2025-71398MedJul 18, 2026
    risk 0.31cvss epss 0.00

    SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network targets, enabling server-side…

  • CVE-2025-11060MedSep 26, 2025
    risk 0.30cvss 5.7epss 0.00

    A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or…

  • CVE-2026-49997MedJul 15, 2026
    risk 0.28cvss 5.4epss 0.00

    SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions disabled through opt.clone().with_perms(false)…

  • CVE-2024-58358MedJul 18, 2026
    risk 0.25cvss 4.9epss 0.00

    SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.

  • CVE-2025-71394MedJul 18, 2026
    risk 0.21cvss 4.3epss 0.00

    SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file…

  • CVE-2026-63763HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the…

  • CVE-2026-63762MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability (disabled by default). Any user able to execute arbitrary queries — including…

  • CVE-2026-63761MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x) has no ES512 variant and the mapping defaults to ES384…

  • CVE-2026-63760HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server…

  • CVE-2026-63759MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.

  • CVE-2026-63758MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time…

  • CVE-2026-63757HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauthenticated attackers can enumerate…

  • CVE-2026-63756HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate…

  • CVE-2026-63755MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELATE update-variant statements) against full record data before enforcing PERMISSIONS FOR SELECT WHERE…

  • CVE-2026-63754MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can…

  • CVE-2026-63753MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

  • CVE-2026-63752MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing…

  • CVE-2026-63751MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record…

  • CVE-2026-63750MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured…

  • CVE-2026-63749MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated…

  • CVE-2026-63748MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden…

  • CVE-2026-63747HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.

  • CVE-2026-63746MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.

  • CVE-2026-63745MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by…

  • CVE-2026-63744MedJul 20, 2026
    risk 0.00cvss 4.1epss 0.00

    SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host…

  • CVE-2026-63743MedJul 20, 2026
    risk 0.00cvss 6.4epss 0.00

    SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:port combination, and the…

  • CVE-2026-63742MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths. Attackers can execute COUNT queries on indexed fields with field-level SELECT restrictions to confirm or recover restricted field values through repeated…

  • CVE-2026-63741MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing authorization checks in the…

  • CVE-2026-63740MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-level permissions should deny…

Page 1 of 2