Executive brief
SurrealDB is an open-source database that supports field-level access controls to hide sensitive data from users. A flaw in versions before 3.1.5 allows authenticated users to bypass these restrictions by using ORDER BY queries on hidden indexed fields, revealing the relative ordering of restricted values even though the field itself appears as null. An attacker with database access can exploit this to infer the hidden values' sort order across records, compromising the confidentiality of protected data.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in SurrealDB's query planner. When a field is protected by a field-level SELECT permission (e.g., DEFINE FIELD ... PERMISSIONS FOR SELECT WHERE ...), the planner withholds the field from WHERE clauses but failed to apply the same restriction to ORDER BY clauses. For indexed fields, the planner leverages the index to sort by value order; the field-level permission is applied only during row projection (nullifying the value), but the row ordering has already been determined by the hidden value. This allows an authenticated user with table-level SELECT permissions to infer the relative ordering of restricted values. The fix, released in 3.1.5, applies the field-permission guard to ORDER BY processing and falls back to sorting after redaction when a restricted field is indexed, preventing the ordering leak.
Affected products
- SurrealDB SurrealDB >= 3.0.0, < 3.1.5
Timeline
- 2026-06-19: disclosed: Advisory GHSA-h4h3-3rfj-x6fq published
- 2026-06-19: patched: Fix released in SurrealDB 3.1.5
- 2026-07-17: other: Duplicate advisory GHSA-2f98-6626-h2p2 published