Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-63735High· 8.1SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
CVE-2026-63740Medium· 6.5SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jpMedium· 6.5SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
CVE-2026-63746Medium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
CVE-2026-63760High· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
CVE-2026-63758Medium· 5.4SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
CVE-2026-63761Medium· 4.3SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
CVE-2026-63751Medium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
CVE-2026-63755Medium· 6.5SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
CVE-2026-63743Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
CVE-2026-63748Medium· 4.3SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
GHSA-6g9v-7gq3-p2c6Medium· 4.3SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
GHSA-fpxg-5xmv-922mMedium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
GHSA-f82j-v89j-mf86Medium· 4.3SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
GHSA-6wqw-vhfr-9999Medium· 4.3SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
GHSA-97vg-427p-8hx5Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
GHSA-wp87-mgvq-5j93Medium· 6.5SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
GHSA-c8jx-96c9-8xrpMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
GHSA-fwg2-gr34-q3w8Medium· 4.3SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
CVE-2026-49997Medium· 5.4SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
GHSA-5qfp-32cf-69jhHigh· 8.8SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
GHSA-4vgr-h27g-cf9pHigh· 8.1SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
GHSA-q729-696q-g9pqHigh· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
GHSA-wjjj-24cx-f28gHigh· 7.5SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
GHSA-q8qp-67f9-wr3fMedium· 6.5SurrealDB vulnerable to Denial of Service due to nested types annotations
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.