Surrealdb

Surrealdb

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 20.07.2026 12:19:43
  • Zuletzt bearbeitet 22.07.2026 15:46:28

SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an allowed hostname to a denied host:por...

  • EPSS 0.21%
  • Veröffentlicht 20.07.2026 12:19:43
  • Zuletzt bearbeitet 22.07.2026 15:47:01

SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths. Attackers can execute COUNT queries on indexed fields with field-level SELECT restrictions to confirm or recover restricted fiel...

  • EPSS 0.27%
  • Veröffentlicht 20.07.2026 12:19:43
  • Zuletzt bearbeitet 23.07.2026 20:17:20

SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing ...

  • EPSS 0.26%
  • Veröffentlicht 20.07.2026 12:19:43
  • Zuletzt bearbeitet 22.07.2026 15:48:36

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-le...

  • EPSS 0.36%
  • Veröffentlicht 20.07.2026 12:19:43
  • Zuletzt bearbeitet 22.07.2026 15:49:10

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file pa...

  • EPSS 0.2%
  • Veröffentlicht 20.07.2026 12:19:43
  • Zuletzt bearbeitet 22.07.2026 15:49:56

SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through graph-edge or back-reference traversals. Attackers with table-level SELECT access can read field values hidden by field-level permi...

  • EPSS 0.23%
  • Veröffentlicht 20.07.2026 12:19:42
  • Zuletzt bearbeitet 22.07.2026 15:51:26

SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role attacker can point an access method ...

  • EPSS 0.35%
  • Veröffentlicht 20.07.2026 12:19:42
  • Zuletzt bearbeitet 22.07.2026 15:50:35

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that c...

  • EPSS 0.26%
  • Veröffentlicht 20.07.2026 12:19:42
  • Zuletzt bearbeitet 23.07.2026 20:17:20

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can ac...

  • EPSS 0.33%
  • Veröffentlicht 20.07.2026 12:19:42
  • Zuletzt bearbeitet 22.07.2026 15:52:42

SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows authenticated Owner-role users to crash the server by uploading a malformed .surml file to the /ml/import endpoint. Attackers can sup...