Denial of Service Vulnerability in SurrealDB by SurrealDB Corp
CVE-2026-63754

7.1HIGH

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63754?

SurrealDB versions prior to 3.1.0 are susceptible to a denial of service vulnerability that can be exploited using malicious LIVE queries. When an unauthorized or authenticated user, possessing merely select permissions, executes a LIVE query with a WHERE clause that results in an error, it leads to failure in all CREATE, UPDATE, and DELETE operations on the targeted table. This issue enables the attacker to disrupt write operations across the board, even affecting root access, until the query is terminated or the session concludes. It is crucial for users to upgrade to the latest version to mitigate this risk.

Affected Version(s)

surrealdb 0 < 3.1.0

surrealdb 3.1.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LucyEgan
.