CVE-2024-58359
- EPSS 0.31%
- Veröffentlicht 18.07.2026 13:10:02
- Zuletzt bearbeitet 12.08.2026 18:46:36
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the...
CVE-2024-58358
- EPSS 0.33%
- Veröffentlicht 18.07.2026 13:10:02
- Zuletzt bearbeitet 12.08.2026 18:48:17
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an inva...
CVE-2024-58357
- EPSS 0.31%
- Veröffentlicht 18.07.2026 13:10:01
- Zuletzt bearbeitet 12.08.2026 18:52:17
SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger ...
CVE-2024-58356
- EPSS 0.2%
- Veröffentlicht 18.07.2026 13:10:00
- Zuletzt bearbeitet 12.08.2026 18:54:25
SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's pe...
CVE-2023-54366
- EPSS 0.28%
- Veröffentlicht 18.07.2026 13:10:00
- Zuletzt bearbeitet 12.08.2026 18:58:10
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed ...
CVE-2026-63309
- EPSS 0.19%
- Veröffentlicht 17.07.2026 16:14:51
- Zuletzt bearbeitet 17.07.2026 18:28:39
SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field values. Attackers can issue ORDER BY queries on indexed restricted fields to recov...