2026 CVE Vulnerabilities

56,936 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63759HIGH7.1SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot...
CVE-2026-63758MEDIUM5.4SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti...
CVE-2026-63757HIGH8.8SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at...
CVE-2026-63756CRITICAL9.2SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows...
CVE-2026-63755HIGH7.1SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i...
CVE-2026-63754HIGH7.1SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause...
CVE-2026-63753MEDIUM5.3SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At...
CVE-2026-63752MEDIUM5.3SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated ...
CVE-2026-63751MEDIUM5.3SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo...
CVE-2026-63750HIGH7.5SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c...
CVE-2026-63749MEDIUM5.3SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis...
CVE-2026-63748MEDIUM5.3SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac...
CVE-2026-63747HIGH8.7SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is ...
CVE-2026-63746HIGH7.1SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references....
CVE-2026-63745MEDIUM5.4SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos...
CVE-2026-63744MEDIUM5.1SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire...
CVE-2026-63743MEDIUM6.4SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us...
CVE-2026-63742MEDIUM5.3SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths...
CVE-2026-63741MEDIUM6.9SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS ...
CVE-2026-63740HIGH7.1SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users...
CVE-2026-63739HIGH8.3SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da...
CVE-2026-63738MEDIUM5.3SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g...
CVE-2026-63737HIGH7.1SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server...
CVE-2026-63736MEDIUM5.1SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the ...
CVE-2026-63735HIGH8.6SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now