๐Ÿ” CVE Alert

CVE-2026-63753

MEDIUM 4.3

SurrealDB before 3.1.0 Authentication Bypass via LIVE Query

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

CWE CWE-613
Vendor surrealdb
Product surrealdb
Published Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for surrealdb surrealdb

Be the first to know when new medium vulnerabilities affecting surrealdb surrealdb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

surrealdb / surrealdb
0 < 3.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4m82-p8cx-f94j vulncheck.com: https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-live-query

Credits

๐Ÿ” LucyEgan ๐Ÿ” addcontent