surrealdb has 40 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 6 in the 90 before. The busiest recent month was July 2026 with 29. The median CVSS is 5.9 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (10) and CWE-674 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 32 prev 6
Weakness classes
Products
- surrealdb 40
Worst active — by depth score
GHSA-5qfp-32cf-69jhHigh· 8.8SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers48CVE-2026-63735High· 8.1SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path45GHSA-4vgr-h27g-cf9pHigh· 8.1SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation45GHSA-cc8f-fcx3-gpjrHigh· 7.7SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter42GHSA-wjjj-24cx-f28gHigh· 7.5SurrealDB has unauthenticated remote DoS via malformed RPC `use` call41
surrealdb vulnerabilities
CVEs affecting surrealdb, newest first. Open any entry for full detail, references, and exploit status.
40 CVEsRSS
CVE-2026-63735High· 8.1SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
CVE-2026-63740Medium· 6.5SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jpMedium· 6.5SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
CVE-2026-63746Medium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
CVE-2026-63760High· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
SurrealDB has Denial of Service in JSON parser due to nested objects
CVE-2026-63758Medium· 5.4SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
CVE-2026-63761Medium· 4.3SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
CVE-2026-63751Medium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
CVE-2026-63755Medium· 6.5SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
CVE-2026-63743Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
CVE-2026-63748Medium· 4.3SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
GHSA-6g9v-7gq3-p2c6Medium· 4.3SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
GHSA-fpxg-5xmv-922mMedium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
GHSA-f82j-v89j-mf86Medium· 4.3SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
GHSA-6wqw-vhfr-9999Medium· 4.3SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
GHSA-97vg-427p-8hx5Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
GHSA-wp87-mgvq-5j93Medium· 6.5SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
GHSA-c8jx-96c9-8xrpMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
GHSA-fwg2-gr34-q3w8Medium· 4.3SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
CVE-2026-49997Medium· 5.4SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
GHSA-5qfp-32cf-69jhHigh· 8.8SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
GHSA-4vgr-h27g-cf9pHigh· 8.1SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
GHSA-q729-696q-g9pqHigh· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
SurrealDB has Denial of Service in JSON parser due to nested objects
GHSA-wjjj-24cx-f28gHigh· 7.5SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
GHSA-q8qp-67f9-wr3fMedium· 6.5SurrealDB vulnerable to Denial of Service due to nested types annotations
SurrealDB vulnerable to Denial of Service due to nested types annotations
GHSA-98fx-66cf-fc7cMedium· 6.5SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
GHSA-vjjx-rfw4-rmfcMedium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
GHSA-6vg3-hgrw-p5gfMedium· 5.4SurrealDB has an Authorization Bypass via Composite Record-id Paths
SurrealDB has an Authorization Bypass via Composite Record-id Paths
GHSA-4v76-cw68-4vc9Medium· 6.5SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
GHSA-gcwr-5mrf-fvchMedium· 5.4SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries