PT-2026-61574 · Surrealdb · Surrealdb

CVE-2026-63758

·

Published

2026-07-01

·

Updated

2026-07-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.1.0
Description An authorization bypass exists in the KILL statement that allows authenticated database users to terminate LIVE SELECT subscriptions belonging to other users. This occurs because the system fails to verify ownership when processing KILL statements targeting specific live query UUIDs, enabling attackers to disrupt real-time data subscriptions.
Recommendations Update SurrealDB to version 3.1.0 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63758
GHSA-GCWR-5MRF-FVCH
GHSA-MF42-3C8Q-X7X8

Affected Products

Surrealdb