CVE-2026-63754
MEDIUMSurrealDB before 3.1.0 Denial of Service via LIVE Query
Title source: cnaDescription
SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can prevent write operations on a table for any user, including root, by registering a LIVE query that triggers evaluation errors until the query is killed or the session ends.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-4v76-cw68-4vc9)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4v76-cw68-4vc9
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.1.0 Denial of Service via LIVE Query
https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-live-query
Scores
CVSS v3
6.5
EPSS
0.0025
EPSS Percentile
17.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-754
Status
published
Products (2)
surrealdb/surrealdb
< 3.1.0 (2 CPE variants)
surrealdb/surrealdb
3.1.0
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026