CVE-2026-63755
- EPSS 0.21%
- Veröffentlicht 20.07.2026 12:19:45
- Zuletzt bearbeitet 22.07.2026 15:19:27
SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELATE update-variant statements) against full record data before enforcing ...
CVE-2026-63756
- EPSS 0.27%
- Veröffentlicht 20.07.2026 12:19:45
- Zuletzt bearbeitet 22.07.2026 15:18:35
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /r...
CVE-2026-63758
- EPSS 0.18%
- Veröffentlicht 20.07.2026 12:19:45
- Zuletzt bearbeitet 22.07.2026 15:10:45
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live que...
CVE-2026-63751
- EPSS 0.17%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 22.07.2026 15:39:37
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operati...
CVE-2026-63745
- EPSS 0.18%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 08.10.2026 16:17:27
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id compon...
CVE-2026-63746
- EPSS 0.29%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 08.10.2026 16:17:27
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FO...
CVE-2026-63747
- EPSS 0.36%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 23.07.2026 20:17:20
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server...
CVE-2026-63748
- EPSS 0.19%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 22.07.2026 15:42:28
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or ex...
CVE-2026-63749
- EPSS 0.21%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 22.07.2026 15:42:06
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actu...
CVE-2026-63750
- EPSS 0.28%
- Veröffentlicht 20.07.2026 12:19:44
- Zuletzt bearbeitet 22.07.2026 15:41:31
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames...