2026 CVE Vulnerabilities
56,936 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63759 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot... |
| CVE-2026-63758 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti... |
| CVE-2026-63757 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at... |
| CVE-2026-63756 | CRITICAL | 9.2 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows... |
| CVE-2026-63755 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i... |
| CVE-2026-63754 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause... |
| CVE-2026-63753 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At... |
| CVE-2026-63752 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated ... |
| CVE-2026-63751 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo... |
| CVE-2026-63750 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c... |
| CVE-2026-63749 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis... |
| CVE-2026-63748 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac... |
| CVE-2026-63747 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is ... |
| CVE-2026-63746 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.... |
| CVE-2026-63745 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos... |
| CVE-2026-63744 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire... |
| CVE-2026-63743 | MEDIUM | 6.4 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us... |
| CVE-2026-63742 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths... |
| CVE-2026-63741 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS ... |
| CVE-2026-63740 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users... |
| CVE-2026-63739 | HIGH | 8.3 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da... |
| CVE-2026-63738 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g... |
| CVE-2026-63737 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server... |
| CVE-2026-63736 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the ... |
| CVE-2026-63735 | HIGH | 8.6 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now