Surrealdb

Surrealdb

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 20.07.2026 12:19:42
  • Zuletzt bearbeitet 22.07.2026 15:53:24

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they...

  • EPSS 0.19%
  • Veröffentlicht 18.07.2026 13:10:15
  • Zuletzt bearbeitet 19.08.2026 17:49:20

SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-net restrictions by redirecting to blocked IP addresses. Attackers can host a public server that redirects to denied network target...

  • EPSS 0.31%
  • Veröffentlicht 18.07.2026 13:10:15
  • Zuletzt bearbeitet 13.08.2026 13:44:42

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to define custom database functions via DEFINE FUNCTION using nested FOR loops....

  • EPSS 0.31%
  • Veröffentlicht 18.07.2026 13:10:14
  • Zuletzt bearbeitet 13.08.2026 13:47:44

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all). ...

  • EPSS 0.25%
  • Veröffentlicht 18.07.2026 13:10:13
  • Zuletzt bearbeitet 19.08.2026 17:51:22

SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to exhaust serve...

  • EPSS 0.25%
  • Veröffentlicht 18.07.2026 13:10:13
  • Zuletzt bearbeitet 13.08.2026 15:03:08

SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can poin...

  • EPSS 0.26%
  • Veröffentlicht 18.07.2026 13:10:12
  • Zuletzt bearbeitet 13.08.2026 15:03:36

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScri...

  • EPSS 0.24%
  • Veröffentlicht 18.07.2026 13:10:11
  • Zuletzt bearbeitet 13.08.2026 14:29:34

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious n...

  • EPSS 0.3%
  • Veröffentlicht 18.07.2026 13:10:10
  • Zuletzt bearbeitet 13.08.2026 14:46:34

SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhand...

  • EPSS 0.25%
  • Veröffentlicht 18.07.2026 13:10:10
  • Zuletzt bearbeitet 13.08.2026 14:48:54

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostn...