surrealdb
A scalable, distributed, collaborative, document-graph database, for the realtime web
Activity
- Latest release
- 4d ago
- Total releases
- 119
- Cadence
- ~5 days
- Last 12 months
- 49
Reach
- Downloads
- 1.4M
- Stars
- 33.0k
Details
- License
- unknown
- First release
- Jul 19, 2022
| Version | Released | |
|---|---|---|
3.3.0-beta.4
pre
|
3.3.0-beta.4
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.1.6
patch
1 CVE
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.6
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.3.0-beta.3
pre
|
3.3.0-beta.3
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.3.0-beta.2
pre
|
3.3.0-beta.2
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.3.0-beta.1
pre
|
3.3.0-beta.1
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.2.4
patch
|
3.2.4
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
3.2.3
patch
|
3.2.3
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
3.2.2
patch
|
3.2.2
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
3.2.1
patch
|
3.2.1
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
3.2.0
minor
|
3.2.0
minor
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.2.0-beta.3
pre
1 CVE
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.2.0-beta.3
pre
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.2.0-beta.2
pre
1 CVE
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.2.0-beta.2
pre
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.2.0-beta.1
pre
1 CVE
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.2.0-beta.1
pre
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.1.5
patch
1 CVE
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.5
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.4
patch
6 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63738
GHSA-hv6h-hc26-q48p
Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read field values hidden from them by field-level SELECT permissions by reaching the records through a graph-edge ( When a table was readable at the table level but carried a field hidden by a field-level permission ( The root cause: the shared ImpactA record user can read the values of fields hidden by field-level SELECT permissions, on tables they already hold table-level SELECT on, by materialising the records through a graph-edge, back-reference, or target-vertex traversal — recovering the values directly, for every record the traversal returns. The disclosure is confined to the field-permission layer: it grants no unauthorised cross-table, cross-record, or cross-namespace/database access. The table's own SELECT permission — including any row-level Table-level enforcement on these traversals landed in 3.1.0 (the fix for GHSA-vjjx-rfw4-rmfc); releases before 3.1.0 additionally exposed whole records on tables the caller could not read, and are covered by that advisory. Patches
Versions 3.1.5 and later are not affected. Workarounds
Resources
Fixed in
3.1.5
References Updated Sep 04, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.4
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.3
patch
7 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63738
GHSA-hv6h-hc26-q48p
Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read field values hidden from them by field-level SELECT permissions by reaching the records through a graph-edge ( When a table was readable at the table level but carried a field hidden by a field-level permission ( The root cause: the shared ImpactA record user can read the values of fields hidden by field-level SELECT permissions, on tables they already hold table-level SELECT on, by materialising the records through a graph-edge, back-reference, or target-vertex traversal — recovering the values directly, for every record the traversal returns. The disclosure is confined to the field-permission layer: it grants no unauthorised cross-table, cross-record, or cross-namespace/database access. The table's own SELECT permission — including any row-level Table-level enforcement on these traversals landed in 3.1.0 (the fix for GHSA-vjjx-rfw4-rmfc); releases before 3.1.0 additionally exposed whole records on tables the caller could not read, and are covered by that advisory. Patches
Versions 3.1.5 and later are not affected. Workarounds
Resources
Fixed in
3.1.5
References Updated Sep 04, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.2
patch
7 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63738
GHSA-hv6h-hc26-q48p
Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read field values hidden from them by field-level SELECT permissions by reaching the records through a graph-edge ( When a table was readable at the table level but carried a field hidden by a field-level permission ( The root cause: the shared ImpactA record user can read the values of fields hidden by field-level SELECT permissions, on tables they already hold table-level SELECT on, by materialising the records through a graph-edge, back-reference, or target-vertex traversal — recovering the values directly, for every record the traversal returns. The disclosure is confined to the field-permission layer: it grants no unauthorised cross-table, cross-record, or cross-namespace/database access. The table's own SELECT permission — including any row-level Table-level enforcement on these traversals landed in 3.1.0 (the fix for GHSA-vjjx-rfw4-rmfc); releases before 3.1.0 additionally exposed whole records on tables the caller could not read, and are covered by that advisory. Patches
Versions 3.1.5 and later are not affected. Workarounds
Resources
Fixed in
3.1.5
References Updated Sep 04, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.1
patch
7 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63738
GHSA-hv6h-hc26-q48p
Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read field values hidden from them by field-level SELECT permissions by reaching the records through a graph-edge ( When a table was readable at the table level but carried a field hidden by a field-level permission ( The root cause: the shared ImpactA record user can read the values of fields hidden by field-level SELECT permissions, on tables they already hold table-level SELECT on, by materialising the records through a graph-edge, back-reference, or target-vertex traversal — recovering the values directly, for every record the traversal returns. The disclosure is confined to the field-permission layer: it grants no unauthorised cross-table, cross-record, or cross-namespace/database access. The table's own SELECT permission — including any row-level Table-level enforcement on these traversals landed in 3.1.0 (the fix for GHSA-vjjx-rfw4-rmfc); releases before 3.1.0 additionally exposed whole records on tables the caller could not read, and are covered by that advisory. Patches
Versions 3.1.5 and later are not affected. Workarounds
Resources
Fixed in
3.1.5
References Updated Sep 04, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.0
minor
7 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63738
GHSA-hv6h-hc26-q48p
Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read field values hidden from them by field-level SELECT permissions by reaching the records through a graph-edge ( When a table was readable at the table level but carried a field hidden by a field-level permission ( The root cause: the shared ImpactA record user can read the values of fields hidden by field-level SELECT permissions, on tables they already hold table-level SELECT on, by materialising the records through a graph-edge, back-reference, or target-vertex traversal — recovering the values directly, for every record the traversal returns. The disclosure is confined to the field-permission layer: it grants no unauthorised cross-table, cross-record, or cross-namespace/database access. The table's own SELECT permission — including any row-level Table-level enforcement on these traversals landed in 3.1.0 (the fix for GHSA-vjjx-rfw4-rmfc); releases before 3.1.0 additionally exposed whole records on tables the caller could not read, and are covered by that advisory. Patches
Versions 3.1.5 and later are not affected. Workarounds
Resources
Fixed in
3.1.5
References Updated Sep 04, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.0-beta.3
pre
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.0-beta.3
pre
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.0-beta.2
pre
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.0-beta.2
pre
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.0-beta.1
pre
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.1.0-beta.1
pre
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.0.5
patch
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.5
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
2.6.5
patch
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
2.6.5
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
2.6.4
patch
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
2.6.4
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.0.4
patch
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.4
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.0.3
patch
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.3
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
2.6.3
patch
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
2.6.3
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.0.2
patch
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.0.1
patch
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.0.0
major
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-jv2j-mqmw-xvv5
Jun 19, 2026
SurrealDB: Denial of Service via deep operator chains
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators. Such a query — for example The root cause: the over-deep tree is later walked recursively, one call per node, when it is dropped, formatted, or lowered for execution — overflowing the thread stack and aborting the process. ImpactAn authenticated user with query-execution privileges can crash a SurrealDB server with a single query containing a long chain of operators. The whole process aborts, denying service to every namespace and database on that instance until it is restarted. The crash occurs during query processing, before any data is read or written (availability only). PatchesA patch introduces a dedicated expression-depth budget —
WorkaroundsUsers unable to patch should consider the following workarounds:
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h4h3-3rfj-x6fq
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A field can be hidden from a user with a field-level SELECT permission ( To satisfy the sort, the planner selects the field's index and walks it in value order; the field-level permission is applied later, when the row is projected, so the value is nulled but the row order already encodes it. The guard that withholds restricted fields from the ImpactWhat an attacker can do:
What it can't do:
PatchesThe query planner now applies the field-permission guard to the The fix is included in SurrealDB 3.1.5. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to George Chen (@geo-chen) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
3.0.0-rc.1
pre
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.0-rc.1
pre
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
2.6.2
patch
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
2.6.2
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
2.6.1
patch
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.0.0-beta.4
pre
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.0-beta.4
pre
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.0.0-beta.3
pre
25 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev |
3.0.0-beta.3
pre
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
2.6.0
minor
26 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63762
GHSA-xx7m-69ff-9crp
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Medium
Network
Low
Low
None
In SurrealDB instances with the scripting capability enabled ( The query consists of using built-in string functions to construct a large string and passing it to the JavaScript runtime for compilation. The exact string size required to trigger the crash varies between SurrealDB versions. Whilst exploiting the vulnerability requires users to be able to run arbitrary queries, if guest access ( ImpactAny user able to execute queries on a SurrealDB instance with scripting enabled ( The underlying cause of the vulnerability is a null pointer dereference in the PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsDeny execution of embedded scripting functions through the configuration of capabilities by starting SurrealDB with the Administrators can also use LinksSurrealDB Documentation - Capabilities SurrealDB Documentation - Guest Access SurrealQL Documentation - Scripting Functions quickjs-ng v0.9 Release Notes https://github.com/surrealdb/surrealdb/pull/6833 https://github.com/surrealdb/surrealdb/pull/6774 Fixed in
2.6.1
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
2.5.0
minor
26 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63762
GHSA-xx7m-69ff-9crp
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Medium
Network
Low
Low
None
In SurrealDB instances with the scripting capability enabled ( The query consists of using built-in string functions to construct a large string and passing it to the JavaScript runtime for compilation. The exact string size required to trigger the crash varies between SurrealDB versions. Whilst exploiting the vulnerability requires users to be able to run arbitrary queries, if guest access ( ImpactAny user able to execute queries on a SurrealDB instance with scripting enabled ( The underlying cause of the vulnerability is a null pointer dereference in the PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsDeny execution of embedded scripting functions through the configuration of capabilities by starting SurrealDB with the Administrators can also use LinksSurrealDB Documentation - Capabilities SurrealDB Documentation - Guest Access SurrealQL Documentation - Scripting Functions quickjs-ng v0.9 Release Notes https://github.com/surrealdb/surrealdb/pull/6833 https://github.com/surrealdb/surrealdb/pull/6774 Fixed in
2.6.1
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.0.0-beta.2
pre
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63762
GHSA-xx7m-69ff-9crp
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Medium
Network
Low
Low
None
In SurrealDB instances with the scripting capability enabled ( The query consists of using built-in string functions to construct a large string and passing it to the JavaScript runtime for compilation. The exact string size required to trigger the crash varies between SurrealDB versions. Whilst exploiting the vulnerability requires users to be able to run arbitrary queries, if guest access ( ImpactAny user able to execute queries on a SurrealDB instance with scripting enabled ( The underlying cause of the vulnerability is a null pointer dereference in the PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsDeny execution of embedded scripting functions through the configuration of capabilities by starting SurrealDB with the Administrators can also use LinksSurrealDB Documentation - Capabilities SurrealDB Documentation - Guest Access SurrealQL Documentation - Scripting Functions quickjs-ng v0.9 Release Notes https://github.com/surrealdb/surrealdb/pull/6833 https://github.com/surrealdb/surrealdb/pull/6774 Fixed in
2.6.1
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev |
3.0.0-beta.2
pre
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
2.4.1
patch
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63762
GHSA-xx7m-69ff-9crp
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Medium
Network
Low
Low
None
In SurrealDB instances with the scripting capability enabled ( The query consists of using built-in string functions to construct a large string and passing it to the JavaScript runtime for compilation. The exact string size required to trigger the crash varies between SurrealDB versions. Whilst exploiting the vulnerability requires users to be able to run arbitrary queries, if guest access ( ImpactAny user able to execute queries on a SurrealDB instance with scripting enabled ( The underlying cause of the vulnerability is a null pointer dereference in the PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsDeny execution of embedded scripting functions through the configuration of capabilities by starting SurrealDB with the Administrators can also use LinksSurrealDB Documentation - Capabilities SurrealDB Documentation - Guest Access SurrealQL Documentation - Scripting Functions quickjs-ng v0.9 Release Notes https://github.com/surrealdb/surrealdb/pull/6833 https://github.com/surrealdb/surrealdb/pull/6774 Fixed in
2.6.1
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.0.0-beta.1
pre
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63762
GHSA-xx7m-69ff-9crp
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Medium
Network
Low
Low
None
In SurrealDB instances with the scripting capability enabled ( The query consists of using built-in string functions to construct a large string and passing it to the JavaScript runtime for compilation. The exact string size required to trigger the crash varies between SurrealDB versions. Whilst exploiting the vulnerability requires users to be able to run arbitrary queries, if guest access ( ImpactAny user able to execute queries on a SurrealDB instance with scripting enabled ( The underlying cause of the vulnerability is a null pointer dereference in the PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsDeny execution of embedded scripting functions through the configuration of capabilities by starting SurrealDB with the Administrators can also use LinksSurrealDB Documentation - Capabilities SurrealDB Documentation - Guest Access SurrealQL Documentation - Scripting Functions quickjs-ng v0.9 Release Notes https://github.com/surrealdb/surrealdb/pull/6833 https://github.com/surrealdb/surrealdb/pull/6774 Fixed in
2.6.1
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev |
3.0.0-beta.1
pre
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.0.0-alpha.18
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.18
pre
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
3.0.0-alpha.17
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.17
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.0.0-alpha.16
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.16
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
2.4.0
minor
27 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63762
GHSA-xx7m-69ff-9crp
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Medium
Network
Low
Low
None
In SurrealDB instances with the scripting capability enabled ( The query consists of using built-in string functions to construct a large string and passing it to the JavaScript runtime for compilation. The exact string size required to trigger the crash varies between SurrealDB versions. Whilst exploiting the vulnerability requires users to be able to run arbitrary queries, if guest access ( ImpactAny user able to execute queries on a SurrealDB instance with scripting enabled ( The underlying cause of the vulnerability is a null pointer dereference in the PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsDeny execution of embedded scripting functions through the configuration of capabilities by starting SurrealDB with the Administrators can also use LinksSurrealDB Documentation - Capabilities SurrealDB Documentation - Guest Access SurrealQL Documentation - Scripting Functions quickjs-ng v0.9 Release Notes https://github.com/surrealdb/surrealdb/pull/6833 https://github.com/surrealdb/surrealdb/pull/6774 Fixed in
2.6.1
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.0.0-alpha.14
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.14
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.0.0-alpha.13
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.13
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.0.0-alpha.12
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.12
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.0.0-alpha.11
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.11
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
3.0.0-alpha.10
pre
28 CVEs
CVE-2026-63735
GHSA-848m-r628-vrxw
Sep 04, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An authenticated user scoped to one namespace/database could invoke a custom API ( The route ImpactWhat an attacker can do:
What it can't do:
PatchesThe namespace/database is now validated against the caller's authenticated level — which the request cannot change — before the endpoint is resolved or run. A target scope outside that level is rejected with
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsSurrealDB thanks sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2025-71390
GHSA-m3c3-78fh-w3w7
Sep 04, 2026
SurrealDB allows bypass of deny-net flags via DNS resolution
Medium
Network
Low
Low
None
SurrealDB offers http functions that can access external network endpoints. A typical, albeit not recommended configuration would be to start SurrealDB with all network connections allowed with the exception of a deny list. For example, An authenticated user of SurrealDB can use bypass this restriction, using When sending SurrealDB statements containing the ImpactThe impact of this vulnerability is circumvention of the For example, if the SurrealDB server blocks requests to internal/private IP addresses because those services don’t require authentication, but an attacker can still use SurrealDBs ability to resolve their hostnames via DNS and invoke them directly using PatchesA patch has been created that checks resolved hostnames against allowed network targets, preventing
WorkaroundsThe possibility of this vulnerability being exploited can be reduced by following an allowlist approach to enabling the http capability surreal start Alternatively, the network access capability can be disabled, using As the impact of this vulnerability depends on the security of the deployment environment of SurrealDB, best practices should be followed within that environment. Fixed in
2.1.8
2.2.6
2.3.6
3.0.0-alpha.7
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63740
GHSA-8rw6-p7m8-63jp
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A The filter removed each denied element by index while walking the array forwards. Because removing an element shifts every later index down, each cut invalidated the indices still pending in the loop, leaving denied elements behind. Field-level permissions are enforced correctly; only the element ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe three permission-filtering paths ( The fix is included in SurrealDB 3.1.4. Workarounds
Resources
Fixed in
3.1.4
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-49997
GHSA-whwg-vh4f-pmmf
Jul 01, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In SurrealDB, records can be connected as a graph: a A user with permission to delete a node could also delete the edges connected to that node, even when the edge table's The automatic edge removal ( ImpactWhat an attacker can do:
What it can't do:
Patches
Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-63761
GHSA-fwg2-gr34-q3w8
Jul 01, 2026
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
When a user configures Users who provide the correct P-521 key type for ES512 will experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384). ImpactAuthentication handshake failures when using ES512 with the correct P-521 key type, and when tokens are verified by external systems expecting real ES512 signatures. This vulnerability cannot be exploited to forge tokens or compromise the integrity or confidentiality of data handled by SurrealDB, as ES384 remains cryptographically strong. PatchesVersions prior to SurrealDB The patches for SurrealDB WorkaroundsUsers should reconfigure affected JWT access methods to use a supported algorithm such as ES384 (with a P-384 key pair) or another supported algorithm. Review any Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-c8jx-96c9-8xrp
Jul 01, 2026
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could learn the value of a hidden field by counting how many records match a guess. When By repeating the count query with different guesses, an attacker can confirm or recover the contents of any restricted field they could not read through a normal ImpactWhat an attacker can do:
What it can't do:
PatchesThe legacy planner (
Versions 3.1.0 and later are not affected. WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wp87-mgvq-5j93
Jul 01, 2026
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
An anonymous caller could create new namespaces and databases on a running SurrealDB instance without holding
ImpactWhat an attacker can do:
What it can't do:
PatchesAll three Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63743
GHSA-97vg-427p-8hx5
Jul 01, 2026
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SurrealDB offers The root cause is in the redirect policy applied to outbound HTTP requests ( ImpactThe impact of this vulnerability is circumvention of the For example, if a SurrealDB operator uses Bounded to:
PatchesThe redirect policy now constructs the A new integration regression test ( Versions 3.1.0 and later are not affected. Workarounds
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-6wqw-vhfr-9999
Jul 01, 2026
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user could read records the table's SELECT permission expression should have hidden, when that expression referenced ImpactA record user binds a value to Read-only impact, bounded to one table. Permission expressions that reference only field names, PatchesA patch has been introduced that re-orders the LIVE notification parameter binding so captured user variables are added first and the trusted document-context and session parameters are added last.
WorkaroundsAffected users who are unable to update should avoid table- Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-f82j-v89j-mf86
Jul 01, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactAn authenticated user with PatchesA patch has been introduced that adds an explicit
This is a behaviour change for applications that relied on RELATE … SET id = … to silently replace existing edges; after the patch those calls return RecordExists instead. Applications that need "create or replace" semantics should use UPSERT (which is correctly permission-gated for the update half). WorkaroundsThe defect only fires when the Where applications must use Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63751
GHSA-fpxg-5xmv-922m
Jul 01, 2026
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SurrealDB lets callers modify records using JSON Patch operations via the ImpactAn authenticated user with permission to issue PatchesA patch has been introduced that rejects an empty
WorkaroundsAffected users who are unable to update should restrict Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63748
GHSA-6g9v-7gq3-p2c6
Jul 01, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A record user with UPDATE access could read field values that field-level SELECT permissions hid from them. Arithmetic operators and ImpactA record user issues an UPDATE that performs an incompatible operation against a hidden field — e.g. PatchesA patch has been introduced that replaces the raw operand in every
WorkaroundsAffected users who are unable to update should not grant UPDATE permission on records whose field-level SELECT permissions are expected to hide values from the same caller. Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4m82-p8cx-f94j
Jul 01, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the ImpactA user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. Patches
Versions 3.1.0 and later are not affected by this issue. WorkaroundsFor unpatched versions, clients should call Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-65rj-r9fh-jp2v
Jul 01, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An anonymous caller could degrade Impact
Separately, PatchesA patch has been introduced that performs the two capability checks before calling
WorkaroundsAffected users who are unable to update should refuse Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63758
GHSA-gcwr-5mrf-fvch
Jul 01, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
The After passing the The affected user's real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user's monitoring live queries. This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53's preliminary finding is Medium, matched by our CVSS v3.1 assessment. ImpactAn authenticated user with database-level access can terminate any other user's live query subscriptions within the same database by issuing a The attack requires knowledge of the target live query UUID. Live query UUIDs are randomly generated, but may be exposed through application logs, shared monitoring dashboards, or other information disclosure vectors. PatchesAn ownership verification check has been introduced in the
WorkaroundsUsers unable to upgrade should consider the following mitigations:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4v76-cw68-4vc9
Jul 01, 2026
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
A While such a ImpactAn authenticated user with PatchesA patch has been introduced that:
WorkaroundsUsers unable to upgrade should restrict the ability of untrusted users to register Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-6vg3-hgrw-p5gf
Jul 01, 2026
SurrealDB has an Authorization Bypass via Composite Record-id Paths
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An authenticated user could bypass permission rules that gated access on parts of a record's id — most commonly tenant-isolation rules of the form When a query referenced part of a composite record id ( ImpactWhat an attacker can do:
What it can't do:
PatchesThe value-path resolver now special-cases
WorkaroundsUsers unable to patch are advised to consider the following workarounds:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63746
GHSA-vjjx-rfw4-rmfc
Jul 01, 2026
SurrealDB: Graph traversal bypasses table SELECT permissions
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
An authenticated record or scope user could read records on any table reachable through a graph edge or Traversing The root cause: ImpactAn authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have PatchesA new per-batch permission cache (
Workarounds
Fixed in
3.1.0
References Updated Sep 04, 2026 · Source: OSV.dev
CVE-2026-63755
GHSA-98fx-66cf-fc7c
Jul 01, 2026
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
A vulnerability was discovered where the user-supplied This vulnerability is confined to the attacker's current database. It does not cross namespace or database isolation boundaries. ImpactAn authenticated user — including Record and Scope users — can read the full contents of any table in the database they are authenticated against, bypassing The most direct exfiltration method requires scripting functions to be enabled ( All tables within the attacker's current database, regardless of table-level PatchesA patch has been introduced that runs
WorkaroundsAffected users who are unable to update may want to:
Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-q8qp-67f9-wr3f
Jul 01, 2026
SurrealDB vulnerable to Denial of Service due to nested types annotations
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path. ImpactAn authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations. PatchesA patch has been introduced that wraps
WorkaroundsRestrict the ability of untrusted users to execute arbitrary queries via the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-wjjj-24cx-f28g
Jul 01, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A single unauthenticated WebSocket message to ImpactAn unauthenticated remote attacker who could reach the PatchesA patch has been introduced that returns a typed
WorkaroundsAffected users who are unable to update should restrict network access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-63760
GHSA-q729-696q-g9pq
Jul 01, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The SurrealDB value and JSON parser did not enforce the configured recursion depth limit when parsing nested This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the value/JSON parser code path. ImpactAn unauthenticated remote attacker can crash a SurrealDB server with a single WebSocket message. No credentials or query execution privileges are required. PatchesA patch enforces the configured recursion depth limit in
WorkaroundsRestrict network access to the WebSocket Fixed in
3.1.0
References
Updated Sep 04, 2026 · Source: OSV.dev
GHSA-4vgr-h27g-cf9p
Jul 01, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The HTTP The HTTP The impact depends on the privilege level of the session that is hijacked. If a root or namespace-level user session is inherited, the attacker can read and modify any data, delete records, and create persistent namespace-level users. If a scoped record user session is inherited, the attacker is limited to that user's permissions. The attack requires no credentials, tokens, or session knowledge — only the ability to send concurrent HTTP requests to the ImpactAn unauthenticated attacker who can reach the PatchesVersions prior to SurrealDB A patch has been introduced that replaces the shared default session with per-request session isolation. Every WorkaroundsThere is no configuration-level mitigation that fully addresses this vulnerability. Network-level controls restricting access to the Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-5qfp-32cf-69jh
Jul 01, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The HTTP "Attached" means sessions registered via Exposure
ImpactFor each attached and authenticated session, an unauthenticated attacker can read, write, and delete any data the session can reach, dump metadata, invalidate sessions, and escalate to that session's privilege level (up to root). An attached session that has not yet authenticated is Patches
Versions 3.1.0 and later are not affected. WorkaroundsNo configuration-level mitigation fully addresses this. For Users unable to upgrade:
Fixed in
3.1.0
References Updated Jul 01, 2026 · Source: OSV.dev
GHSA-cc8f-fcx3-gpjr
Jun 19, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
SurrealDB's full-text search lets you define a text analyzer whose File access is meant to be restricted by the ImpactThe file is read with the privileges of the SurrealDB process, so a database However recovering the process's command line and environment could expose startup root credentials ( The read on the underlying filesystem is bounded by what the SurrealDB process can reach — any file readable by the OS user it runs as — so the impact scales with how the process is run and what is mounted into it. PatchesA patch has been included in SurrealDB 3.1.5. File access is now secure by default. WorkaroundsUsers unable to upgrade are advised to consider the following:
References
AcknowledgementsThanks to Jan Kahmen (@kah-ja) for finding and reporting this issue. Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
GHSA-h5rg-8p7f-47g2
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
SurrealDB fetches the JWKS document for a JWT or record access method using a bare ImpactWhat an attacker can do:
What it can't do:
PatchesThe JWKS fetcher now applies a redirect policy that re-validates every redirect target against the configured network capabilities (mirroring
Workarounds
References
Fixed in
3.1.5
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2026-63763
GHSA-3v2x-9xcv-2v2v
Jan 22, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
Network
Low
Low
Unprivileged users (for example, those with the database editor role) can create or modify fields in records that contain functions or This results in a confused deputy vulnerability: an attacker with limited privileges can define a malicious function or future field that performs privileged actions. When a higher-privileged user (such as a root owner or namespace administrator) executes the function or queries or modifies that record, the function executes with their elevated permissions. ImpactAn attacker who can create or update function/future fields can plant logic that executes with a privileged user’s context. If a privileged user performs a write that touches the malicious field, the attacker can achieve full privilege escalation (e.g., create a root owner and take over the server). If a privileged user performs a read action on the malicious field, this attack vector could still be potentially be used to perform limited denial of service or, in the specific case where the network capability was explicitly enabled and unrestricted, exfiltrate database information over the network. PatchesVersions prior to 2.5.0 and 3.0.0-beta.3 are vulnerable. For SurrealDB 3.0, Further to this patches for 2.5.0 and 3.0.0-beta.3:
For existing apis, events, fields and functions defined prior to upgrading to 2.5.0 or 3.0.0-beta.3 WorkaroundsUsers unable to patch are advised to evaluate their use of the database to identify where low privileged users are able to define logic subsequently executed by privileged users, such as apis, functions, futures fields and events, and recommended to minimise these instances. ReferencesFixed in
2.5.0
3.0.0-beta.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2025-11060
GHSA-7vm2-j586-vcvc
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Medium
Network
Low
Low
This allows a record or guest user with permissions to run live query subscriptions on a table to observe unauthorised records within the same table, when another user is altering or deleting these records, bypassing access controls. ImpactA record or guest user with permissions to run live query subscriptions on a table is able to observe unauthorised records within the same table, with unauthorised records returned when deleted, or when records matching the WHERE conditions are created, updated, or deleted, by another user. This impacts confidentiality, limited to the table the attacker has access to, and with the data disclosed dependent of the actions taken by other users. PatchesA patch has been created for the following versions:
WorkaroundsAssess the impact of users with permissions on table records effectively having full read access to the table, use separate tables if required, with impacts to functionality. Fixed in
2.1.9
2.2.8
2.3.8
3.0.0-alpha.8
References
Updated Sep 26, 2025 · Source: OSV.dev |
3.0.0-alpha.10
pre
Dependencies (57)
+ 49 more
Changelog
Compare changes
|