surrealdb
55 known vulnerabilities affecting surrealdb products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-58368 | Medium | 0.7% | 7.5 | SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS header… | |
| CVE-2024-58362 | Medium | 0.6% | 8.8 | SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary… | |
| CVE-2026-63757 | Medium | 0.5% | 8.8 | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where … | |
| CVE-2026-63747 | Medium | 0.5% | 7.5 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the… | |
| CVE-2026-63760 | Medium | 0.5% | 7.5 | SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in … | |
| CVE-2026-63763 | Medium | 0.5% | 8.8 | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privil… | |
| CVE-2026-63739 | Medium | 0.5% | 7.7 | SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFI… | |
| CVE-2023-54366 | Medium | 0.5% | 8.8 | SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, a… | |
| CVE-2026-63756 | Medium | 0.4% | 8.1 | SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race conditi… | |
| CVE-2026-63735 | Medium | 0.4% | 8.1 | SurrealDB versions before 3.2.0 fail to validate namespace and database scope in… | |
| CVE-2024-58366 | Medium | 0.3% | 8.5 | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Ex… | |
| CVE-2025-71390 | Medium | 0.2% | 8.8 | SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails t… | |
| CVE-2025-71392 | Medium | 0.2% | 8.0 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to prop… | |
| CVE-2025-71398 | Medium | 0.2% | 7.6 | SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allow… | |
| CVE-2026-63750 | Low | 0.5% | 5.3 | SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_… | |
| CVE-2024-58370 | Low | 0.5% | 6.5 | SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when pars… | |
| CVE-2026-63737 | Low | 0.5% | 6.5 | SurrealDB versions before 3.1.5 contain a denial of service vulnerability where … | |
| CVE-2024-58358 | Low | 0.5% | 4.9 | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in rol… | |
| CVE-2026-63734 | Low | 0.5% | 4.9 | SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the… | |
| CVE-2024-58357 | Low | 0.5% | 6.5 | SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in t… | |
| CVE-2024-58359 | Low | 0.5% | 6.5 | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the… | |
| CVE-2024-58361 | Low | 0.5% | 6.5 | SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerabi… | |
| CVE-2024-58364 | Low | 0.5% | 6.5 | SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerabi… | |
| CVE-2024-58365 | Low | 0.5% | 6.5 | SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in t… | |
| CVE-2024-58369 | Low | 0.5% | 6.5 | SurrealDB versions before 1.1.1 fail to properly validate invocation of custom p… | |
| CVE-2026-63754 | Low | 0.5% | 6.5 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability where … | |
| CVE-2026-63759 | Low | 0.5% | 6.5 | SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind … | |
| CVE-2026-63762 | Low | 0.5% | 6.5 | SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service … | |
| CVE-2026-63746 | Low | 0.4% | 6.5 | SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when tr… | |
| CVE-2026-63741 | Low | 0.4% | 6.5 | SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATA… | |
| CVE-2026-63755 | Low | 0.4% | 6.5 | SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statement… | |
| CVE-2026-63749 | Low | 0.4% | 4.3 | SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability i… | |
| CVE-2026-63740 | Low | 0.4% | 6.5 | SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on a… | |
| CVE-2026-63753 | Low | 0.4% | 4.3 | SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subs… | |
| CVE-2024-58363 | Low | 0.3% | 6.3 | SurrealDB before 1.5.4 fails to properly validate authentication when a scope us… | |
| CVE-2026-63748 | Low | 0.3% | 4.3 | SurrealDB versions before 3.1.0 contain an information disclosure vulnerability … | |
| CVE-2026-63744 | Low | 0.3% | 4.1 | SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in t… | |
| CVE-2026-63736 | Low | 0.3% | 4.1 | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in t… | |
| CVE-2025-71396 | Low | 0.3% | 6.5 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enfo… | |
| CVE-2025-71397 | Low | 0.3% | 6.5 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authen… | |
| CVE-2026-63758 | Low | 0.3% | 5.4 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in… | |
| CVE-2025-71391 | Low | 0.3% | 6.5 | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in t… | |
| CVE-2026-63742 | Low | 0.3% | 4.3 | SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass v… | |
| CVE-2026-63751 | Low | 0.3% | 4.3 | SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerab… | |
| CVE-2026-63738 | Low | 0.3% | 4.3 | SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permiss… | |
| CVE-2026-63752 | Low | 0.3% | 4.3 | SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the REL… | |
| CVE-2026-63761 | Low | 0.3% | 4.3 | SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT acces… | |
| CVE-2025-71393 | Low | 0.3% | 6.5 | SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursio… | |
| CVE-2025-71395 | Low | 0.3% | 6.5 | SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the… | |
| CVE-2026-63743 | Low | 0.2% | 6.4 | SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redire… |
Page 1 of 2
Next →