Denial of Service Vulnerability in SurrealDB by SurrealDB Corp
CVE-2026-63754
7.1HIGH
What is CVE-2026-63754?
SurrealDB versions prior to 3.1.0 are susceptible to a denial of service vulnerability that can be exploited using malicious LIVE queries. When an unauthorized or authenticated user, possessing merely select permissions, executes a LIVE query with a WHERE clause that results in an error, it leads to failure in all CREATE, UPDATE, and DELETE operations on the targeted table. This issue enables the attacker to disrupt write operations across the board, even affecting root access, until the query is terminated or the session concludes. It is crucial for users to upgrade to the latest version to mitigate this risk.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
