← All vendors

surrealdb

55 known vulnerabilities affecting surrealdb products.

Products

surrealdb 55

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2024-58368 Medium 0.7% 7.5 SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS header…
CVE-2024-58362 Medium 0.6% 8.8 SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary…
CVE-2026-63757 Medium 0.5% 8.8 SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where …
CVE-2026-63747 Medium 0.5% 7.5 SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the…
CVE-2026-63760 Medium 0.5% 7.5 SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in …
CVE-2026-63763 Medium 0.5% 8.8 SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privil…
CVE-2026-63739 Medium 0.5% 7.7 SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFI…
CVE-2023-54366 Medium 0.5% 8.8 SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, a…
CVE-2026-63756 Medium 0.4% 8.1 SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race conditi…
CVE-2026-63735 Medium 0.4% 8.1 SurrealDB versions before 3.2.0 fail to validate namespace and database scope in…
CVE-2024-58366 Medium 0.3% 8.5 SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Ex…
CVE-2025-71390 Medium 0.2% 8.8 SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails t…
CVE-2025-71392 Medium 0.2% 8.0 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to prop…
CVE-2025-71398 Medium 0.2% 7.6 SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allow…
CVE-2026-63750 Low 0.5% 5.3 SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_…
CVE-2024-58370 Low 0.5% 6.5 SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when pars…
CVE-2026-63737 Low 0.5% 6.5 SurrealDB versions before 3.1.5 contain a denial of service vulnerability where …
CVE-2024-58358 Low 0.5% 4.9 SurrealDB versions before 2.1.0 contain a denial of service vulnerability in rol…
CVE-2026-63734 Low 0.5% 4.9 SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the…
CVE-2024-58357 Low 0.5% 6.5 SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in t…
CVE-2024-58359 Low 0.5% 6.5 SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the…
CVE-2024-58361 Low 0.5% 6.5 SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerabi…
CVE-2024-58364 Low 0.5% 6.5 SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerabi…
CVE-2024-58365 Low 0.5% 6.5 SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in t…
CVE-2024-58369 Low 0.5% 6.5 SurrealDB versions before 1.1.1 fail to properly validate invocation of custom p…
CVE-2026-63754 Low 0.5% 6.5 SurrealDB versions before 3.1.0 contain a denial of service vulnerability where …
CVE-2026-63759 Low 0.5% 6.5 SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind …
CVE-2026-63762 Low 0.5% 6.5 SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service …
CVE-2026-63746 Low 0.4% 6.5 SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when tr…
CVE-2026-63741 Low 0.4% 6.5 SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATA…
CVE-2026-63755 Low 0.4% 6.5 SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statement…
CVE-2026-63749 Low 0.4% 4.3 SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability i…
CVE-2026-63740 Low 0.4% 6.5 SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on a…
CVE-2026-63753 Low 0.4% 4.3 SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subs…
CVE-2024-58363 Low 0.3% 6.3 SurrealDB before 1.5.4 fails to properly validate authentication when a scope us…
CVE-2026-63748 Low 0.3% 4.3 SurrealDB versions before 3.1.0 contain an information disclosure vulnerability …
CVE-2026-63744 Low 0.3% 4.1 SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in t…
CVE-2026-63736 Low 0.3% 4.1 SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in t…
CVE-2025-71396 Low 0.3% 6.5 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enfo…
CVE-2025-71397 Low 0.3% 6.5 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authen…
CVE-2026-63758 Low 0.3% 5.4 SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in…
CVE-2025-71391 Low 0.3% 6.5 SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in t…
CVE-2026-63742 Low 0.3% 4.3 SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass v…
CVE-2026-63751 Low 0.3% 4.3 SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerab…
CVE-2026-63738 Low 0.3% 4.3 SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permiss…
CVE-2026-63752 Low 0.3% 4.3 SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the REL…
CVE-2026-63761 Low 0.3% 4.3 SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT acces…
CVE-2025-71393 Low 0.3% 6.5 SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursio…
CVE-2025-71395 Low 0.3% 6.5 SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the…
CVE-2026-63743 Low 0.2% 6.4 SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redire…
Page 1 of 2 Next →