← Browse

Surrealdb

42 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-63733 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements wit… 2026-07-20 CVE-2026-63734 MEDIUM 6.9 Surrealdb — SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that … 2026-07-20 CVE-2026-63735 HIGH 8.6 Surrealdb — SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing a… 2026-07-20 CVE-2026-63736 MEDIUM 5.1 Surrealdb — SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates… 2026-07-20 CVE-2026-63737 HIGH 7.1 Surrealdb — SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash … 2026-07-20 CVE-2026-63738 MEDIUM 5.3 Surrealdb — SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed… 2026-07-20 CVE-2026-63739 HIGH 8.3 Surrealdb — SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that… 2026-07-20 CVE-2026-63740 HIGH 7.1 Surrealdb — SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for re… 2026-07-20 CVE-2026-63741 MEDIUM 6.9 Surrealdb — SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processi… 2026-07-20 CVE-2026-63742 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT … 2026-07-20 CVE-2026-63743 MEDIUM 5.3 Surrealdb — SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authen… 2026-07-20 CVE-2026-63744 MEDIUM 5.1 Surrealdb — SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows H… 2026-07-20 CVE-2026-63745 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can sp… 2026-07-20 CVE-2026-63746 HIGH 7.1 Surrealdb — SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-r… 2026-07-20 CVE-2026-63747 HIGH 8.7 Surrealdb — SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics w… 2026-07-20 CVE-2026-63748 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with… 2026-07-20 CVE-2026-63749 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions wh… 2026-07-20 CVE-2026-63750 MEDIUM 6.9 Surrealdb — SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql W… 2026-07-20 CVE-2026-63751 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations… 2026-07-20 CVE-2026-63752 MEDIUM 5.3 Surrealdb — SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows auth… 2026-07-20 CVE-2026-63753 MEDIUM 5.3 Surrealdb — SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state c… 2026-07-20 CVE-2026-63754 HIGH 7.1 Surrealdb — SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WH… 2026-07-20 CVE-2026-63755 HIGH 7.1 Surrealdb — SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH… 2026-07-20 CVE-2026-63756 CRITICAL 9.2 Surrealdb — SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint t… 2026-07-20 CVE-2026-63757 HIGH 8.7 Surrealdb — SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method … 2026-07-20 CVE-2026-63758 MEDIUM 5.3 Surrealdb — SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allow… 2026-07-20 CVE-2026-63759 HIGH 7.1 Surrealdb — SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested … 2026-07-20 CVE-2026-63760 HIGH 8.7 Surrealdb — SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when… 2026-07-20 CVE-2026-63761 MEDIUM 5.3 Surrealdb — SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with AL… 2026-07-20 CVE-2026-63762 MEDIUM 6 Surrealdb — SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded … 2026-07-20 CVE-2026-63763 HIGH 7.5 Surrealdb — SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. … 2026-07-20 CVE-2025-71390 MEDIUM 5.8 Surrealdb — SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostna… 2026-07-18 CVE-2025-71391 HIGH 7.1 Surrealdb — SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows auth… 2026-07-18 CVE-2025-71392 CRITICAL 9.4 Surrealdb — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field na… 2026-07-18 CVE-2025-71393 MEDIUM 6 Surrealdb — SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions… 2026-07-18 CVE-2025-71394 LOW 2.3 Surrealdb — SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that … 2026-07-18 CVE-2025-71395 HIGH 7.1 Surrealdb — SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that… 2026-07-18 CVE-2025-71396 LOW 2.3 Surrealdb — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time l… 2026-07-18 CVE-2025-71397 HIGH 7.1 Surrealdb — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or ED… 2026-07-18 CVE-2025-71398 MEDIUM 5.8 Surrealdb — SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to byp… 2026-07-18 CVE-2026-63309 MEDIUM 5.3 Surrealdb — SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticate… 2026-07-17 CVE-2026-49997 MEDIUM 5.4 Surrealdb — SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.… 2026-07-15