CVE-2026-63754: SurrealDB before 3.1.0 Denial of Service via LIVE Query
SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can prevent write operations on a table for any user, including root, by registering a LIVE query that triggers evaluation errors until the query is killed or the session ends.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Until the upgrade to 3.1.0, limit/monitor the ability of authenticated users with select permissions to register LIVE queries on tables to prevent malicious LIVE queries with WHERE clauses that evaluate to errors.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63754?
CVE-2026-63754 has a severity rating of high at 7.1.
What are the effects of CVE-2026-63754?
CVE-2026-63754 allows an attacker to perform a denial of service by causing CREATE, UPDATE, and DELETE operations to fail.
How do I fix CVE-2026-63754?
To fix CVE-2026-63754, upgrade SurrealDB to version 3.1.0 or later.
Who is affected by CVE-2026-63754?
Authenticated users with only select permission on SurrealDB versions before 3.1.0 are affected by CVE-2026-63754.
What type of vulnerability is CVE-2026-63754?
CVE-2026-63754 is a denial of service vulnerability related to malicious LIVE queries.