<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T05:21:14.675499+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341481</id>
    <title>EUVD-2026-341481</title>
    <updated>2026-10-07T05:21:14.737508+00:00</updated>
    <content>EUVD-2026-341481</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63746</id>
    <title>fkie_cve-2026-63746</title>
    <updated>2026-10-07T05:21:14.737549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vjjx-rfw4-rmfc</id>
    <title>GHSA-vjjx-rfw4-rmfc — SurrealDB: Graph traversal bypasses table SELECT permissions</title>
    <updated>2026-10-07T05:21:14.737584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: surrealdb</p>
<p>An authenticated record or scope user could read records on any table reachable through a graph edge or `REFERENCES TO` back-reference, regardless of that table's `PERMISSIONS FOR select` clause.</p>
<p>Traversing `SELECT * FROM source-&gt;edge-&gt;target` returned full documents from `target` even when `target` was defined as `PERMISSIONS FOR select NONE`. The same bypass extended through multi-hop chains, so any table reachable by a sequence of edges from a readable starting point was exposed.</p>
<p>The root cause: `GraphEdgeScan` and `ReferenceScan` fetched records straight from storage without routing them through `Document::pluck_select`, so the target table's permission expression was never consulted.</p>
<p>### Impact</p>
<p>An authenticated record or scope user can read records on any table reachable through a chain of graph edges or back-references from a table they have `select` on, regardless of the target's `PERMISSIONS FOR select` clause. Confidentiality-only and bounded to the caller's current database — namespace and database isolation are unaffected.</p>
<p>### Patches</p>
<p>A new per-batch permission cache (`exec::permission::CachedTableSelect`) resolves each target table's `SELECT` permission once and filters yielded values through `check_permission_for_value`, matching the regular `SELECT` code path.</p>
<p>- Versions 3.1.0 and later are not affected.</p>
<p>### Workarounds</p>
<p>- Remove `select` permission on edge tables whose targets should be hidden.
- Use namespace or database isolation as the primary bound…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vjjx-rfw4-rmfc"/>
  </entry>
</feed>
