PatchSiren

surrealdb CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW surrealdb CVE published 2026-07-18

CVE-2025-71396

CVE-2025-71396 is a low-severity vulnerability in SurrealDB, a database management system, that can lead to denial of service via JavaScript scripting. The vulnerability exists in SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2. An authenticated attacker can submit long-running JavaScript functions to exhaust server resources and cause a denial of service when the scripting cap [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2025-71395

CVE-2025-71395 is a high-severity vulnerability in SurrealDB versions before 2.2.2, caused by the string::replace function failing to restrict resulting string length when using regex patterns. This allows an authenticated attacker to craft a malicious query to exhaust server memory through unbounded string allocations, causing denial of service. Users should apply the patch to prevent potential denial of [truncated]

MEDIUM surrealdb CVE published 2026-07-18

CVE-2025-71393

CVE-2025-71393 is a medium-severity vulnerability in SurrealDB before version 2.2.2. The vulnerability occurs when scripting is enabled and native functions contain embedded JavaScript that issues new queries, allowing authenticated attackers to bypass recursion limits and trigger infinite recursion, leading to memory exhaustion. This can have significant operational impacts on systems using affected vers [truncated]

CRITICAL surrealdb CVE published 2026-07-18

CVE-2025-71392

CVE-2025-71392 is a critical vulnerability in SurrealDB, allowing authenticated users to inject malicious SurrealQL code via the command-line export command. This issue affects SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2. The vulnerability enables privilege escalation and potential root-level takeover of the SurrealDB instance. Users of SurrealDB, especially those with cust [truncated]

MEDIUM surrealdb CVE published 2026-07-18

CVE-2025-71390

CVE-2025-71390 is a medium-severity vulnerability in SurrealDB that allows an authenticated user to bypass network access controls by invoking http functions with a hostname that resolves to a denied IP address. This vulnerability affects SurrealDB versions before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier). The vulnerability has a CVSS score of 5.8 and a CVSS severity of MEDIUM.

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58370

CVE-2024-58370 is a high-severity vulnerability in SurrealDB, a database management system. The vulnerability exists due to the lack of recursion depth limits when parsing nested SurrealQL statements, including IF, RELATE, and attribute access idioms. This can be exploited by authorized attackers to submit queries with excessive nesting depth, causing a stack overflow and crashing the server. The vulnerab [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58369

CVE-2024-58369 is a high-severity vulnerability in SurrealDB versions before 1.1.1, caused by inadequate validation of custom parameters and functions. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service. The vulnerability has a CVSS score of 7.1 and is classified as HIGH. Affected users should prioritize updates to prevent poten [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58368

SurrealDB versions before 1.1.0 are vulnerable to a denial-of-service attack due to improper parsing of ID, DB, and NS headers in HTTP REST API requests containing special characters. This issue allows unauthenticated attackers to send crafted HTTP requests that trigger an uncaught exception, causing the server to crash. The vulnerability has a high CVSS score of 8.7, indicating a significant risk to affe [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58367

CVE-2024-58367 is a high-severity vulnerability in SurrealDB versions before 2.0.4, allowing authorized users to access unauthorized field values through various query techniques. The vulnerability has a CVSS score of 7.1 and is classified as HIGH. This issue affects SurrealDB deployments, and users should review official advisories to validate affected scope, severity, and vendor guidance. The CVE record [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58365

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-18T14:17:09.460Z and has not been modified since then. SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58364

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-18T14:17:09.320Z and has not been modified since then. The vulnerability affects SurrealDB versions before 1.2.1 and involves an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. This could lead to denial of service attacks if [truncated]

MEDIUM surrealdb CVE published 2026-07-18

CVE-2024-58363

CVE-2024-58363 is a medium-severity vulnerability in SurrealDB, a database management system. The issue arises from improper authentication validation when a user switches databases using the USE clause or use method. An attacker with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists. This can lead to unauthorized action [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58362

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-18T14:17:09.047Z and has not been modified since then. SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. This allows an unauthenticated attacker to enco [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58361

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-18T14:17:08.917Z and has not been modified since then. SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. This vulnerability allows authorized clients to execute malformed queries that cause a panic i [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58359

A denial of service vulnerability exists in SurrealDB versions before 2.1.0. The vulnerability is triggered when using the ORDER BY rand() clause, which can cause a panic in the sorting function, resulting in a server crash. This issue can be exploited by authorized clients executing specific queries. The vulnerability has a CVSS score of 7.1 and is rated as HIGH. Users of SurrealDB versions before 2.1.0 [truncated]

MEDIUM surrealdb CVE published 2026-07-18

CVE-2024-58358

CVE-2024-58358 is a denial of service vulnerability in SurrealDB versions before 2.1.0. Privileged owner users can define users with nonexistent roles, which can be exploited by attackers to trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability exists in the role conversion pr [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2024-58357

CVE-2024-58357 is an uncaught exception vulnerability in SurrealDB versions before 2.1.0. The vulnerability exists in the rand::time() function, which panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reliably trigger server panics and cause denial of service. The CVSS score for this vulnerability is 7.1, indicating a high severity. [truncated]

HIGH surrealdb CVE published 2026-07-18

CVE-2023-54366

CVE-2023-54366 is a high-severity vulnerability in SurrealDB, a database management system. The vulnerability arises from SurrealDB's default setting of table permissions to FULL instead of NONE, allowing for SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. This issue affects SurrealDB versions before 1.0.1 and can be exploited by attackers with database access or unau [truncated]

MEDIUM surrealdb CVE published 2026-07-17

CVE-2026-63309

CVE-2026-63309 is a medium-severity vulnerability in SurrealDB, a database management system. The issue arises from the failure to apply field-level SELECT permissions to ORDER BY clauses in versions prior to 3.1.5. This oversight allows authenticated users to infer the relative ordering of restricted field values by issuing ORDER BY queries on indexed restricted fields. Consequently, attackers can recove [truncated]