Technology · crates.io
surrealdb (crates.io) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 118 vulnerabilities in surrealdb (crates.io): 0 in the last 7 days and 107 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Duplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to…, was published on 20 July 2026.
- Last 7 days
- 0
- Last 90 days
- 107
- Critical, all time
- 0
- Exploited in the wild
- 0
About surrealdb (crates.io)
A multi-model database written in Rust designed for serverless, web, and mobile applications.
Latest surrealdb (crates.io) vulnerabilities
- Duplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitationlowCVSS 3.1
- Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objectslowCVSS 3.1
- SurrealDB ES512 algorithm silently downgraded to ES384mediumCVSS 4.3
- SurrealDB JSON parser denial of service via uncontrolled recursionhighCVSS 7.5
- Duplicate Advisory: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live QuerieslowCVSS 3.1
- SurrealDB authorization bypass in KILL statementmediumCVSS 5.4
- SurrealDB permission bypass via WHERE clause evaluationmediumCVSS 6.5
- Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth levellowCVSS 3.1
- Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissionslowCVSS 3.1
- Duplicate Advisory: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messageslowCVSS 3.1
- SurrealDB graph traversal bypasses table SELECT permissionsmediumCVSS 6.5
- Duplicate Advisory: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirectlowCVSS 3.1
- SurrealDB field-level permission bypass in JSON PatchmediumCVSS 4.3
- SurrealDB port-specific deny-net rule bypass on HTTP redirectmediumCVSS 6.4
- Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`lowCVSS 3.1
- SurrealDB information disclosure via error messagesmediumCVSS 4.3
- SurrealDB array element-level SELECT permissions bypassmediumCVSS 6.5
- Duplicate Advisory: SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record userslowCVSS 3.1
- SurrealDB permissions bypass via PERMISSIONS clausemediumCVSS 4.3
- Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissionslowCVSS 3.1
- SurrealDB field-level SELECT permission bypass via graph traversalsmediumCVSS 4.3
- Duplicate Advisory: Custom API route lets authenticated callers override namespace/database scope via URL pathlowCVSS 3.1
- Duplicate Advisory: SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversalslowCVSS 3.1
- SurrealDB custom API route namespace/database scope bypasshighCVSS 8.1
- CVE-2026-63761: SurrealDB cryptographic algorithm substitution in JWT access methodmediumCVSS 4.3EPSS 0.3%
Most severe surrealdb (crates.io) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-58362: SurrealDB query injection in RPC API signin and signup operationshighCVSS 8.8EPSS 0.6%
- CVE-2023-54366: SurrealDB insecure default table permissionshighCVSS 8.8EPSS 0.5%
- SurrealDB deny-net bypass via DNS resolutionhighCVSS 8.8
- SurrealDB insecure default table permissionshighCVSS 8.8
- SurrealDB session hijacking via HTTP RPC session leakhighCVSS 8.8
- CVE-2024-58366: SurrealDB format string vulnerability in rquickjs scripting enginehighCVSS 8.5EPSS 0.6%
- CVE-2026-63735: SurrealDB authorization bypass in custom API routeshighCVSS 8.1EPSS 0.4%
- SurrealDB custom API route namespace/database scope bypasshighCVSS 8.1
- SurrealDB privilege escalation via HTTP RPC session race conditionhighCVSS 8.1
- SurrealDB SurrealQL injection in backup export/importhighCVSS 8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 32 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 40 | 0 | |
| 20 Jul 2026 | 35 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/surrealdb.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "surrealdb (crates.io) vulnerabilities", https://junglewise.ai/threats/technologies/surrealdb, 26 September 2026.