Skip to content

SurrealDB security advisories

54 advisories across SurrealDB

Company profile
Advisory
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High8.1Sep 4
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Medium6.5Aug 14
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
Medium5.4Jul 1
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
Medium4.3Jul 1
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
Medium4.3Jul 1
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
Medium6.5Jul 1
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
Medium6.4Jul 1
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
Medium4.3Jul 1
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
Medium4.3Jul 1
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
Medium4.3Jul 1
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
Medium4.3Jul 1
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
Medium4.3Jul 1
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
Medium5.3Jul 1
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
Medium5.4Jul 1
SurrealDB: unchecked exceptional condition
Medium6.5Jul 1
SurrealDB has an Authorization Bypass via Composite Record-id Paths
Medium5.4Jul 1
SurrealDB: Graph traversal bypasses table SELECT permissions
Medium6.5Jul 1
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
Medium6.5Jul 1
SurrealDB vulnerable to Denial of Service due to nested types annotations
Medium6.5Jul 1
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
High7.5Jul 1
SurrealDB has Denial of Service in JSON parser due to nested objects
High7.5Jul 1
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
High8.1Jul 1
SurrealDB: session fixation
High8.8Jul 1
SurrealDB: Denial of Service via deep operator chains
Medium6.5Jun 19
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
Medium4.3Jun 19
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
Medium4.3Jun 19
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
High7.7Jun 19
SurrealDB: SSRF via JWKS URL , Redirect Following in JWT Key Fetch
Medium4.1Jun 19
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
MediumFeb 12
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
HighJan 22
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
MediumApr 11, 2025
SurrealDB CPU exhaustion via custom functions result in total DoS
HighApr 11, 2025
SurrealDB no JavaScript script function default timeout could facilitate DoS
LowApr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
HighApr 11, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
CriticalApr 11, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
LowApr 10, 2025
SurrealDB vulnerable to memory exhaustion via nested functions and scripts
MediumApr 10, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
HighApr 10, 2025
SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
LowDec 16, 2024
SurrealDB has an Uncaught Exception Sorting Tables by Random Order
Medium6.5Nov 22, 2024
SurrealDB has an Uncaught Exception Handling Nonexistent Role
Medium4.9Nov 22, 2024
SurrealDB has an Uncaught Exception in Function Generating Random Time
Medium6.5Nov 22, 2024
SurrealDB: Improper Authorization in Select Permissions
High6.5Oct 8, 2024
SurrealDB has an Uncaught Exception Handling Parsing Errors on Empty Strings
High6.5Oct 8, 2024
Untrusted Query Object Evaluation in RPC API
High8.8Sep 11, 2024
SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User
Medium6.3Jul 11, 2024
Externally Controlled Format String in Scripting Functions
High8.5Feb 21, 2024
Uncaught Exception in Macro Expecting Native Function to Exist
Medium6.5Feb 21, 2024
Uncaught Exception Handling Parsing Errors on Line Terminators
Medium6.5Feb 21, 2024
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
High7.5Jan 19, 2024
Uncontrolled Recursion in SurrealQL Parsing
Medium6.5Jan 18, 2024
Uncaught Exception processing HTTP Headers in SurrealDB
High7.5Jan 18, 2024
Uncaught Exception in surrealdb
Medium6.5Jan 18, 2024
SurrealDB: Full Table Permissions by Default
High8.8Dec 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.