surrealdb has 40 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 6 in the 90 before. The busiest recent month was July 2026 with 29. The median CVSS is 5.9 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (10) and CWE-674 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 32 prev 6
Weakness classes
Products
- surrealdb 40
Worst active — by depth score
GHSA-5qfp-32cf-69jhHigh· 8.8SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers48CVE-2026-63735High· 8.1SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path45GHSA-4vgr-h27g-cf9pHigh· 8.1SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation45GHSA-cc8f-fcx3-gpjrHigh· 7.7SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter42GHSA-wjjj-24cx-f28gHigh· 7.5SurrealDB has unauthenticated remote DoS via malformed RPC `use` call41
surrealdb vulnerabilities
CVEs affecting surrealdb, newest first. Open any entry for full detail, references, and exploit status.
40 CVEsRSS
GHSA-65rj-r9fh-jp2vMedium· 5.3SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
GHSA-4m82-p8cx-f94jMedium· 4.3SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
CVE-2026-63738Medium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
GHSA-h5rg-8p7f-47g2Medium· 4.1SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
GHSA-cc8f-fcx3-gpjrHigh· 7.7SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
GHSA-h4h3-3rfj-x6fqMedium· 4.3SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
GHSA-hv6h-hc26-q48pMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
GHSA-jv2j-mqmw-xvv5Medium· 6.5SurrealDB: Denial of Service via deep operator chains
SurrealDB: Denial of Service via deep operator chains
CVE-2026-63762MediumSurrealDB vulnerable to Denial of Service through scripting function memory edge case
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
CVE-2026-63763HighSurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions