CVE-2026-63754

MEDIUM

SurrealDB before 3.1.0 Denial of Service via LIVE Query

Title source: cna
STIX 2.1

Description

SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can prevent write operations on a table for any user, including root, by registering a LIVE query that triggers evaluation errors until the query is killed or the session ends.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-4v76-cw68-4vc9)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4v76-cw68-4vc9
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.1.0 Denial of Service via LIVE Query
https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-live-query

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (2)
surrealdb/surrealdb < 3.1.0 (2 CPE variants)
surrealdb/surrealdb 3.1.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026