SurrealDB versions before 3.1.0 contain a time-of-check...
Critical severity
Unreviewed
Published
Jul 20, 2026
to the GitHub Advisory Database
•
Updated Jul 20, 2026
Description
Published by the National Vulnerability Database
Jul 20, 2026
Published to the GitHub Advisory Database
Jul 20, 2026
Last updated
Jul 20, 2026
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.
References