GHSA-9567-jfw6-h5pcMediumCVSS 4.3

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when...

Published
July 20, 2026
Last Modified
July 20, 2026

🔗 CVE IDs covered (1)

📋 Description

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

🔗 References (4)