« Volver al listado

Surrealdb

Surrealdb: vulnerabilidades y CVE

Surrealdb tiene 58 vulnerabilidades publicadas, 58 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE58
Últimos 12 meses58
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-102876Alta (8.6)0.27%—29 sept 2026
SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS…
CVE-2026-63763Alta (7.5)0.50%—20 jul 2026
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing…
CVE-2026-63762Media (6)0.45%—20 jul 2026
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability (disabled by default). Any…
CVE-2026-63761Media (5.3)0.28%—20 jul 2026
SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x)…
CVE-2026-63760Alta (8.7)0.52%—20 jul 2026
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON…
CVE-2026-63759Alta (7.1)0.45%—20 jul 2026
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust…
CVE-2026-63758Media (5.3)0.31%—20 jul 2026
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL…
CVE-2026-63757Alta (8.7)0.54%—20 jul 2026
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership…
CVE-2026-63756Crítica (9.2)0.37%—20 jul 2026
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can…
CVE-2026-63755Alta (7.1)0.36%—20 jul 2026
SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELATE update-variant statements) against…
CVE-2026-63754Alta (7.1)0.45%—20 jul 2026
SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to…
CVE-2026-63753Media (5.3)0.35%—20 jul 2026
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials…
CVE-2026-63752Media (5.3)0.28%—20 jul 2026
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission.…
CVE-2026-63751Media (5.3)0.29%—20 jul 2026
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from…
CVE-2026-63750Media (6.9)0.49%—20 jul 2026
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer.…
CVE-2026-63749Media (5.3)0.36%—20 jul 2026
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against…
CVE-2026-63748Media (5.3)0.33%—20 jul 2026
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages.…
CVE-2026-63747Alta (8.7)0.52%—20 jul 2026
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the…
CVE-2026-63746Alta (7.1)0.40%—20 jul 2026
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of…
CVE-2026-63745Media (5.3)0.25%—20 jul 2026
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission…
CVE-2026-63744Media (5.1)0.32%—20 jul 2026
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role…
CVE-2026-63743Media (5.3)0.25%—20 jul 2026
SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated users to circumvent port-scoped --deny-net rules. Attackers can chain an HTTP redirect from an…
CVE-2026-63742Media (5.3)0.29%—20 jul 2026
SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths. Attackers can execute COUNT queries on indexed fields with field-level SELECT restrictions to…
CVE-2026-63741Media (6.9)0.37%—20 jul 2026
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by…
CVE-2026-63740Alta (7.1)0.36%—20 jul 2026
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read…
CVE-2026-63739Alta (8.3)0.48%—20 jul 2026
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process.…
CVE-2026-63738Media (5.3)0.28%—20 jul 2026
SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through graph-edge or back-reference traversals. Attackers with table-level SELECT access can read field…
CVE-2026-63737Alta (7.1)0.49%—20 jul 2026
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of…
CVE-2026-63736Media (5.1)0.31%—20 jul 2026
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL hostname string against allow-lists without checking resolved IP addresses. An Owner role…
CVE-2026-63735Alta (8.6)0.37%—20 jul 2026
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services23
  2. T1499.004 Application or System Exploitation9
  3. T1005 Data from Local System6
  4. T1499 Endpoint Denial of Service5
  5. T1190 Exploit Public-Facing Application4
  6. T1203 Exploitation for Client Execution3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.