<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:48:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-341493</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341493</link>
      <description>EUVD-2026-341493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341493</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63758</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63758</link>
      <description>&lt;p&gt;SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users&amp;#39; LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users&amp;#39; LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63758</guid>
    </item>
    <item>
      <title>GHSA-gcwr-5mrf-fvch — SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcwr-5mrf-fvch</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: surrealdb&lt;/p&gt;
&lt;p&gt;The `KILL` statement is used to terminate `LIVE SELECT` subscriptions that capture real-time changes to data within a table. The `KILL` statement implementation in `core/src/expr/statements/kill.rs` verifies that the requesting user has database-level access, but does not verify that the requesting user is the owner of the live query being terminated.
 
After passing the `valid_for_db()` check, the `KILL` statement resolves the live query UUID, looks up the corresponding live query entry, and immediately deletes it without comparing the requesting user&amp;#39;s identity against the live query owner. This allows any authenticated user with database-level access to terminate any live query in that database, regardless of who created it.
 
The affected user&amp;#39;s real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user&amp;#39;s monitoring live queries.
 
This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53&amp;#39;s preliminary finding is Medium, matched by our CVSS v3.1 assessment.
 
### Impact
 
An authenticated user with database-level access can terminate any other user&amp;#39;s live query subscriptions within the same database by issuing a `KILL` statement with the target live query&amp;#39;s UUID. This impacts availability by silently disrupting real-time data subscri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: surrealdb&lt;/p&gt;
&lt;p&gt;The `KILL` statement is used to terminate `LIVE SELECT` subscriptions that capture real-time changes to data within a table. The `KILL` statement implementation in `core/src/expr/statements/kill.rs` verifies that the requesting user has database-level access, but does not verify that the requesting user is the owner of the live query being terminated.
 
After passing the `valid_for_db()` check, the `KILL` statement resolves the live query UUID, looks up the corresponding live query entry, and immediately deletes it without comparing the requesting user&amp;#39;s identity against the live query owner. This allows any authenticated user with database-level access to terminate any live query in that database, regardless of who created it.
 
The affected user&amp;#39;s real-time subscription silently stops receiving updates with no notification that the live query was terminated. The same attack works across privilege levels: a low-privilege record-scoped user can terminate a root user&amp;#39;s monitoring live queries.
 
This issue was discovered and patched during a code audit and penetration test of SurrealDB by cure53, the severity defined within cure53&amp;#39;s preliminary finding is Medium, matched by our CVSS v3.1 assessment.
 
### Impact
 
An authenticated user with database-level access can terminate any other user&amp;#39;s live query subscriptions within the same database by issuing a `KILL` statement with the target live query&amp;#39;s UUID. This impacts availability by silently disrupting real-time data subscri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcwr-5mrf-fvch</guid>
    </item>
  </channel>
</rss>
