Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Surrealdb HIGH 8.8
CVE-2026-63763

SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with th…

Fix: 2.5.0+
Fix from $1,950 2026-07-20
Surrealdb HIGH 7.5
CVE-2026-63760

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or…

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63759

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attacke…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63762

SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is e…

Fix: 2.6.1+
Fix from $1,600 2026-07-20
Surrealdb HIGH 8.8
CVE-2026-63757

SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without …

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Surrealdb HIGH 8.1
CVE-2026-63756

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to …

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63754

SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cau…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63755

SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON D…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 5.4
CVE-2026-63758

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to termi…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb HIGH 7.5
CVE-2026-63747

SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unau…

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Surrealdb HIGH 7.5
CVE-2026-63750

SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attacker…

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63746

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 5.4
CVE-2026-63745

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb HIGH 7.7
CVE-2026-63739

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or O…

Fix: 3.1.5+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63740

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elemen…

Fix: 3.1.4+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63741

SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauth…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.4
CVE-2026-63743

SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Surrealdb HIGH 8.1
CVE-2026-63735

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints …

Fix: 3.2.0+
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63737

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long…

Fix: 3.1.5+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63733

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with en…

Fix: 3.2.0+
Fix from $1,600 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2025-71397

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespac…

Fix: 2.0.5 / 2.1.5+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2025-71396

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting f…

Fix: 2.0.5 / 2.1.5+
Fix from $1,600 2026-07-18
Surrealdb HIGH 8.8
CVE-2025-71390

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access r…

Fix: 2.1.8 / 2.2.6+
Fix from $1,950 2026-07-18
Surrealdb HIGH 8.0
CVE-2025-71392

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command.…

Fix: 2.0.5 / 2.1.5+
Fix from $1,950 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58369

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server p…

Fix: 1.1.1+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2025-71391

SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. …

Fix: 2.2.2+
Fix from $1,600 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2025-71393

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issue…

Fix: 2.0.5 / 2.1.5+
Fix from $1,600 2026-07-18
Surrealdb HIGH 8.8
CVE-2024-58362

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without re…

Fix: 1.5.5+
Fix from $1,950 2026-07-18
Surrealdb HIGH 7.5
CVE-2024-58368

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenti…

Fix: 1.1.0+
Fix from $1,950 2026-07-18
Surrealdb MEDIUM 6.5
CVE-2024-58364

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line termi…

Fix: 1.2.1+
Fix from $1,600 2026-07-18