Loading...
Skip to main content
crates.io (Rust)

SurrealDB Security Analysis

SurrealDB has 21 known security vulnerabilities in crates.io (Rust). Upgrade to version 3.1.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

21 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 3.1.0

Upgrading to 3.1.0 or later resolves all 21 known vulnerabilities in SurrealDB. Update Cargo.toml: SurrealDB = "3.1.0"

Is SurrealDB in your project?

Check if you're affected and upgrade to 3.1.0 to stay secure.

21
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

21 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2025-71392
SurrealDB server-takeover via SurrealQL injection on backup import
CRITICAL
All versions2.2.2, 2.1.5, 2.0.5
CVE-2024-58362
Untrusted Query Object Evaluation in RPC API
HIGH
All versions1.5.5, 2.0.0-beta.3
CVE-2026-63763
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
HIGH
All versions2.5.0, 3.0.0-beta.3
CVE-2024-58366
Externally Controlled Format String in Scripting Functions
HIGH
All versions1.1.1
CVE-2024-58368
Uncaught Exception processing HTTP Headers in SurrealDB
HIGH
All versions1.1.0
CVE-2025-71397
SurrealDB CPU exhaustion via custom functions result in total DoS
HIGH
All versions2.2.2, 2.1.5, 2.0.5
CVE-2025-71395
SurrealDB memory exhaustion via string::replace using regex
HIGH
All versions2.2.2, 2.1.5, 2.0.5
CVE-2025-71391
SurrealDB has uncaught exception in Net module that leads to database crash
HIGH
All versions2.2.2, 2.1.5, 2.0.5
GHSA-5qfp-32cf-69jh
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
HIGH
All versions3.1.0
CVE-2024-58367
Improper Authorization in Select Permissions
HIGH
All versions2.0.4
CVE-2024-58361
SurrealDB has an Uncaught Exception Handling Parsing Errors on Empty Strings
HIGH
All versions2.0.4
GHSA-4vgr-h27g-cf9p
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
HIGH
All versions3.1.0
CVE-2024-58365
Uncaught Exception in Macro Expecting Native Function to Exist
MEDIUM
All versions1.2.0
CVE-2024-58364
Uncaught Exception Handling Parsing Errors on Line Terminators
MEDIUM
All versions1.2.1
CVE-2025-71398
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
MEDIUM
All versions2.2.2, 2.1.5, 2.0.5
CVE-2026-63762
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
MEDIUM
All versions2.6.1, 3.0.0-beta.3
CVE-2024-58359
SurrealDB has an Uncaught Exception Sorting Tables by Random Order
MEDIUM
All versions2.1.0
CVE-2024-58357
SurrealDB has an Uncaught Exception in Function Generating Random Time
MEDIUM
All versions2.1.0
CVE-2025-71393
SurrealDB vulnerable to memory exhaustion via nested functions and scripts
MEDIUM
All versions2.2.2, 2.1.5, 2.0.5
CVE-2025-11060
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
MEDIUM
All versions2.3.8, 2.2.8, 2.1.9 (+1 more)
CVE-2024-58363
SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User
MEDIUM
All versions1.5.4, 2.0.0-alpha.6

About This Data

Vulnerability data for SurrealDB is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related crates.io (Rust) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of SurrealDB.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed