Surrealdb
42 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-63733
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements wit…
2026-07-20
CVE-2026-63734
MEDIUM 6.9
Surrealdb — SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that …
2026-07-20
CVE-2026-63735
HIGH 8.6
Surrealdb — SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing a…
2026-07-20
CVE-2026-63736
MEDIUM 5.1
Surrealdb — SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates…
2026-07-20
CVE-2026-63737
HIGH 7.1
Surrealdb — SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash …
2026-07-20
CVE-2026-63738
MEDIUM 5.3
Surrealdb — SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed…
2026-07-20
CVE-2026-63739
HIGH 8.3
Surrealdb — SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that…
2026-07-20
CVE-2026-63740
HIGH 7.1
Surrealdb — SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for re…
2026-07-20
CVE-2026-63741
MEDIUM 6.9
Surrealdb — SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processi…
2026-07-20
CVE-2026-63742
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT …
2026-07-20
CVE-2026-63743
MEDIUM 5.3
Surrealdb — SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authen…
2026-07-20
CVE-2026-63744
MEDIUM 5.1
Surrealdb — SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows H…
2026-07-20
CVE-2026-63745
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can sp…
2026-07-20
CVE-2026-63746
HIGH 7.1
Surrealdb — SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-r…
2026-07-20
CVE-2026-63747
HIGH 8.7
Surrealdb — SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics w…
2026-07-20
CVE-2026-63748
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with…
2026-07-20
CVE-2026-63749
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions wh…
2026-07-20
CVE-2026-63750
MEDIUM 6.9
Surrealdb — SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql W…
2026-07-20
CVE-2026-63751
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations…
2026-07-20
CVE-2026-63752
MEDIUM 5.3
Surrealdb — SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows auth…
2026-07-20
CVE-2026-63753
MEDIUM 5.3
Surrealdb — SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state c…
2026-07-20
CVE-2026-63754
HIGH 7.1
Surrealdb — SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WH…
2026-07-20
CVE-2026-63755
HIGH 7.1
Surrealdb — SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH…
2026-07-20
CVE-2026-63756
CRITICAL 9.2
Surrealdb — SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint t…
2026-07-20
CVE-2026-63757
HIGH 8.7
Surrealdb — SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method …
2026-07-20
CVE-2026-63758
MEDIUM 5.3
Surrealdb — SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allow…
2026-07-20
CVE-2026-63759
HIGH 7.1
Surrealdb — SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested …
2026-07-20
CVE-2026-63760
HIGH 8.7
Surrealdb — SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when…
2026-07-20
CVE-2026-63761
MEDIUM 5.3
Surrealdb — SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with AL…
2026-07-20
CVE-2026-63762
MEDIUM 6
Surrealdb — SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded …
2026-07-20
CVE-2026-63763
HIGH 7.5
Surrealdb — SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. …
2026-07-20
CVE-2025-71390
MEDIUM 5.8
Surrealdb — SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostna…
2026-07-18
CVE-2025-71391
HIGH 7.1
Surrealdb — SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows auth…
2026-07-18
CVE-2025-71392
CRITICAL 9.4
Surrealdb — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field na…
2026-07-18
CVE-2025-71393
MEDIUM 6
Surrealdb — SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions…
2026-07-18
CVE-2025-71394
LOW 2.3
Surrealdb — SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that …
2026-07-18
CVE-2025-71395
HIGH 7.1
Surrealdb — SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that…
2026-07-18
CVE-2025-71396
LOW 2.3
Surrealdb — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time l…
2026-07-18
CVE-2025-71397
HIGH 7.1
Surrealdb — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or ED…
2026-07-18
CVE-2025-71398
MEDIUM 5.8
Surrealdb — SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to byp…
2026-07-18
CVE-2026-63309
MEDIUM 5.3
Surrealdb — SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticate…
2026-07-17
CVE-2026-49997
MEDIUM 5.4
Surrealdb — SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.…
2026-07-15