Junglewise Threat Intelligence

SurrealDB insufficient session expiration in LIVE query subscriptions

Severity: medium · CVSS 4.3 · Published 2026-07-01

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a database that supports real-time data updates through 'LIVE' queries. A vulnerability was found where these real-time updates continue to be sent to a user even after their session has expired, they have logged out, or they have switched to a different account on the same connection. This could allow a user to continue seeing sensitive data updates they are no longer authorized to access until the network connection is manually closed.

Technical details

A vulnerability in SurrealDB's LIVE SELECT mechanism causes subscriptions to retain the initial authentication state ($auth, $token, etc.) indefinitely. The server evaluates table- and row-level PERMISSIONS using this stale state rather than the current session state. Consequently, if a session is invalidated, expires via TTL, or the user re-authenticates as a different principal on the same connection, the original subscription remains active and continues delivering notifications. This is a confidentiality-only issue (CWE-613) as it does not permit unauthorized writes. The issue is resolved in version 3.1.0 by ensuring RPC methods like signin, signup, and invalidate properly trigger a cleanup of associated live queries.

Affected products

  • SurrealDB surrealdb < 3.1.0

Timeline

  • 2026-05-27: disclosed: Initial disclosure in surrealdb/surrealdb repository
  • 2026-07-01: advisory: GitHub Advisory published

References

Related threats