surrealdb Security Analysis
surrealdb has 21 known security vulnerabilities in crates.io (Rust). Upgrade to version 3.1.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 3.1.0
Upgrading to 3.1.0 or later resolves all 21 known vulnerabilities in surrealdb. Update Cargo.toml: surrealdb = "3.1.0"
Is surrealdb in your project?
Check if you're affected and upgrade to 3.1.0 to stay secure.
Vulnerabilities
21 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2025-71392 SurrealDB server-takeover via SurrealQL injection on backup import | CRITICAL | All versions | 2.2.2, 2.1.5, 2.0.5 |
| CVE-2024-58362 Untrusted Query Object Evaluation in RPC API | HIGH | All versions | 1.5.5, 2.0.0-beta.3 |
| CVE-2026-63763 SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions | HIGH | All versions | 2.5.0, 3.0.0-beta.3 |
| CVE-2024-58366 Externally Controlled Format String in Scripting Functions | HIGH | All versions | 1.1.1 |
| CVE-2024-58368 Uncaught Exception processing HTTP Headers in SurrealDB | HIGH | All versions | 1.1.0 |
| CVE-2025-71397 SurrealDB CPU exhaustion via custom functions result in total DoS | HIGH | All versions | 2.2.2, 2.1.5, 2.0.5 |
| CVE-2025-71395 SurrealDB memory exhaustion via string::replace using regex | HIGH | All versions | 2.2.2, 2.1.5, 2.0.5 |
| CVE-2025-71391 SurrealDB has uncaught exception in Net module that leads to database crash | HIGH | All versions | 2.2.2, 2.1.5, 2.0.5 |
| GHSA-5qfp-32cf-69jh SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers | HIGH | All versions | 3.1.0 |
| CVE-2024-58367 Improper Authorization in Select Permissions | HIGH | All versions | 2.0.4 |
| CVE-2024-58361 SurrealDB has an Uncaught Exception Handling Parsing Errors on Empty Strings | HIGH | All versions | 2.0.4 |
| GHSA-4vgr-h27g-cf9p SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation | HIGH | All versions | 3.1.0 |
| CVE-2024-58365 Uncaught Exception in Macro Expecting Native Function to Exist | MEDIUM | All versions | 1.2.0 |
| CVE-2024-58364 Uncaught Exception Handling Parsing Errors on Line Terminators | MEDIUM | All versions | 1.2.1 |
| CVE-2025-71398 SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF) | MEDIUM | All versions | 2.2.2, 2.1.5, 2.0.5 |
| CVE-2026-63762 SurrealDB vulnerable to Denial of Service through scripting function memory edge case | MEDIUM | All versions | 2.6.1, 3.0.0-beta.3 |
| CVE-2024-58359 SurrealDB has an Uncaught Exception Sorting Tables by Random Order | MEDIUM | All versions | 2.1.0 |
| CVE-2024-58357 SurrealDB has an Uncaught Exception in Function Generating Random Time | MEDIUM | All versions | 2.1.0 |
| CVE-2025-71393 SurrealDB vulnerable to memory exhaustion via nested functions and scripts | MEDIUM | All versions | 2.2.2, 2.1.5, 2.0.5 |
| CVE-2025-11060 SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions | MEDIUM | All versions | 2.3.8, 2.2.8, 2.1.9 (+1 more) |
| CVE-2024-58363 SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User | MEDIUM | All versions | 1.5.4, 2.0.0-alpha.6 |
About This Data
Vulnerability data for surrealdb is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related crates.io (Rust) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of surrealdb.