Executive brief
SurrealDB is a real-time database that supports live subscriptions (LIVE SELECT queries) for applications to receive streaming updates. An authorization flaw in the KILL statement allows any authenticated database user to terminate other users' live subscriptions without ownership verification, disrupting real-time data delivery and breaking multi-tenant isolation guarantees. This vulnerability affects all versions before 3.1.0.
Technical details
The KILL statement in SurrealDB is used to terminate LIVE SELECT subscriptions. The vulnerable code in core/src/expr/statements/kill.rs performs only database-level access verification (valid_for_db() check) but fails to verify that the requesting user is the owner of the live query being terminated. After passing the access check, the KILL statement resolves the live query UUID, looks up the corresponding entry, and immediately deletes it without comparing the requesting user's identity against the live query owner. This allows any authenticated database user to terminate any live query, including those owned by higher-privilege users. The attack is network-accessible and requires only database-level authentication credentials. The affected user's subscription silently stops receiving updates without notification. Fix: version 3.1.0 introduced an ownership verification check that compares the requesting user's authentication context against the live query owner before allowing deletion.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: disclosed: Original advisory GHSA-gcwr-5mrf-fvch published
- 2026: patched: Fix released in version 3.1.0