Authentication Bypass in SurrealDB Affects Real-Time Notification Systems
CVE-2026-63753
5.3MEDIUM
What is CVE-2026-63753?
SurrealDB versions prior to 3.1.0 contain a vulnerability where the system fails to properly refresh the authentication state during LIVE SELECT subscriptions when there are changes in session status. This oversight allows attackers to continue receiving real-time notifications even after their session credentials have been revoked or expired, remaining connected until the connection is terminated. This incident raises significant security concerns for applications relying on real-time data updates.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
