SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can prevent write operations on a table for any user, including root, by registering a LIVE query that triggers evaluation errors until the query is killed or the session ends.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:* |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Surrealdb
Surrealdb surrealdb |
|
| Vendors & Products |
Surrealdb
Surrealdb surrealdb |
Mon, 20 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can prevent write operations on a table for any user, including root, by registering a LIVE query that triggers evaluation errors until the query is killed or the session ends. | |
| Title | SurrealDB before 3.1.0 Denial of Service via LIVE Query | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-20T12:04:45.256Z
Updated: 2026-07-28T01:05:46.549Z
Reserved: 2026-07-18T12:30:08.354Z
Link: CVE-2026-63754
Updated: 2026-07-20T12:52:37.053Z
No data.
No data.