surrealdb vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-63738Mediumsurrealdb: SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversalsGHSA-H4H3-3RFJ-X6FQMediumsurrealdb: SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted fieldGHSA-CC8F-FCX3-GPJRHighsurrealdb: SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filterGHSA-H5RG-8P7F-47G2Mediumsurrealdb: SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key FetchGHSA-XX7M-69FF-9CRPMediumsurrealdb: SurrealDB vulnerable to Denial of Service through scripting function memory edge caseGHSA-3V2X-9XCV-2V2VHighsurrealdb: SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and FunctionsCVE-2025-11060MediumSurrealDB: SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query SubscriptionsCVE-2025-71398Mediumsurrealdb: SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)GHSA-PXW4-94J3-V9PFHighsurrealdb: SurrealDB CPU exhaustion via custom functions result in total DoSGHSA-3824-QMFQ-2QV7Lowsurrealdb: SurrealDB no JavaScript script function default timeout could facilitate DoSGHSA-3633-G6MG-P6QQHighsurrealdb: SurrealDB memory exhaustion via string::replace using regex CVE-2025-71392Criticalsurrealdb: SurrealDB server-takeover via SurrealQL injection on backup importGHSA-2CVJ-G5R5-JRRGLowsurrealdb: SurrealDB has local file read of 2-column TSV files via analyzers GHSA-M7RC-8W7M-R9QRMediumsurrealdb: SurrealDB vulnerable to memory exhaustion via nested functions and scriptsGHSA-RQ86-9M6R-CM3GHighsurrealdb: SurrealDB has uncaught exception in Net module that leads to database crashCVE-2024-58356Lowsurrealdb: SurrealDB has Silent Failure to Overwrite Table Definition of Relation TypeGHSA-M52V-24P8-654FMediumsurrealdb: SurrealDB has an Uncaught Exception Sorting Tables by Random OrderCVE-2024-58358Mediumsurrealdb: SurrealDB has an Uncaught Exception Handling Nonexistent RoleGHSA-H4F5-H82V-5W4RMediumsurrealdb: SurrealDB has an Uncaught Exception in Function Generating Random TimeCVE-2024-58367Highsurrealdb: SurrealDB: Improper Authorization in Select PermissionsGHSA-QJRV-V6QP-X99XHighsurrealdb: SurrealDB has an Uncaught Exception Handling Parsing Errors on Empty StringsGHSA-64F8-PJGR-9WMRHighsurrealdb: Untrusted Query Object Evaluation in RPC APIGHSA-GH9F-6XM2-C4J2Mediumsurrealdb: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope UserGHSA-Q3GG-M8HR-H4X4Highsurrealdb: Externally Controlled Format String in Scripting FunctionsGHSA-6WR5-JMPR-MJCXMediumsurrealdb: Uncaught Exception in Macro Expecting Native Function to Exist

Stop the waste.
Protect your environment with Kodem.