Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63754

SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clauses that evaluate to errors cause all CREATE, UPDATE, and DELETE operations on the watched table to fail. An authenticated user with only select permission can prevent write operations on a table for any user, including root, by registering a LIVE query that triggers evaluation errors until the query is killed or the session ends.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 16.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-63754


Contact Us

Shodan ® - All rights reserved