{"id":"GHSA-4v76-cw68-4vc9","title":"SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required","summary":"SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required","severity":"medium","cvss":6.5,"cwe":["CWE-754"],"vendor":"surrealdb","product":"surrealdb","ecosystem":"rust","affected":["surrealdb < 3.1.0"],"patched":["surrealdb 3.1.0"],"published":"2026-07-01","updated":"2026-07-01","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4v76-cw68-4vc9","references":[{"url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4v76-cw68-4vc9"},{"url":"https://github.com/surrealdb/surrealdb/commit/af835eb199ad2327a04c42101d11aff21fce7e47"},{"url":"https://github.com/surrealdb/surrealdb/commit/b29e03f0714d1c4ec091fc6f27f1edbe243b8aec"},{"url":"https://github.com/advisories/GHSA-4v76-cw68-4vc9"}],"tags":["ghsa","rust"],"ingestedAt":"2026-07-01T20:16:35.266Z","slug":"GHSA-4v76-cw68-4vc9","body":"## Overview\n\nA `LIVE` query whose `WHERE` clause evaluates to an error caused the source data modifier (the user creating, updating, or deleting a record on the watched table) to fail instead. Calling any arbitrary SurrealQL function with a typed parameter and passing a value of the wrong type — for example `LIVE SELECT * FROM t WHERE string::trim(deny)` — triggered an evaluation error inside the LIVE notification path. That error then propagated through to the triggering write, rolling back the attempted change.\n\nWhile such a `LIVE` query was registered, all `CREATE`, `UPDATE`, and `DELETE` operations on the watched table failed — including those issued by a root user — for as long as the registration remained active. Registering the `LIVE` required `select` permission on the table; no other permission on the table was needed.\n\n### Impact\n\nAn authenticated user with `select` permission on a table can prevent all `CREATE`, `UPDATE`, and `DELETE` operations on that table — by any other user, up to and including root — for the lifetime of a single registered `LIVE` query. Service is restored when the `LIVE` query is killed or the session that registered it ends.\n\n### Patches\n\nA patch has been introduced that:\n\n1. **Decouples LIVE query evaluation errors from the source transaction** — when `lq_check` returns an error during the LIVE notification path, the error is now reported to the LIVE subscriber as an `Action::Error` notification and the LIVE processing path returns `Ok(())`. The triggering write proceeds normally.\n2. **Defers the error notification until after the permission check** — the `Action::Error` notification is only delivered after the LIVE subscription's `PERMISSIONS` clause has been evaluated, so unauthorised subscribers do not learn even that an error occurred (closing an information-disclosure side channel introduced by the first part of the fix).\n\n- Versions 3.1.0 and later are not affected by this issue.\n\n### Workarounds\n\nUsers unable to upgrade should restrict the ability of untrusted users to register `LIVE` queries by removing the `select` permission on tables they want to keep writeable, or by gating LIVE registration at the application layer.\n\n## Affected packages\n\n- `surrealdb < 3.1.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `surrealdb 3.1.0`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}