<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:34:50.341642+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341486</id>
    <title>EUVD-2026-341486</title>
    <updated>2026-10-04T13:34:50.388347+00:00</updated>
    <content>EUVD-2026-341486</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63751</id>
    <title>fkie_cve-2026-63751</title>
    <updated>2026-10-04T13:34:50.388383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63751"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fpxg-5xmv-922m</id>
    <title>GHSA-fpxg-5xmv-922m — SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`</title>
    <updated>2026-10-04T13:34:50.388416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: surrealdb</p>
<p>SurrealDB lets callers modify records using JSON Patch operations via the `UPDATE … PATCH` statement (and SDK equivalents such as `db.patch()`). One of those operations is `copy`, which duplicates one field's value into another field of the same record. A `PATCH` with an empty `from` — for example, `UPDATE thing:1 PATCH [{ op: 'copy', from: '', path: '/leak' }]` — was treated as "copy the entire record" and duplicated every field, including fields the caller has no permission to read, into the destination field the caller chose. The permission filter that hides protected field values from the response only knew to hide the *original* protected field names, not the new destinations, so the protected values were returned to the caller intact under the new field name.</p>
<p>### Impact</p>
<p>An authenticated user with permission to issue `UPDATE … PATCH` against a record could read the values of any field on that record, regardless of field-level `PERMISSIONS FOR select` restrictions. The leak is confidentiality-only, and bounded to the fields of the single record the caller targets per PATCH request — it does not expose other records on the same table or any data outside that record's scope.</p>
<p>### Patches</p>
<p>A patch has been introduced that rejects an empty `from` pointer at parse time for both `copy` and `move` operations.</p>
<p>- Versions 3.1.0 and later are not affected by this issue.</p>
<p>### Workarounds</p>
<p>Affected users who are unable to update should restrict `UPDATE … PATCH` to callers who alr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fpxg-5xmv-922m"/>
  </entry>
</feed>
