CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jul 19, 2026

newpanjing simpleui Missing Authentication Vulnerability in AjaxAdmin AJAX Endpoint

A vulnerability exists in newpanjing simpleui version 2026.01.13, specifically within the AjaxAdmin component's AJAX endpoint. The issue arises in the self.get_action function of simpleui/admin.py, where authentication checks are bypassed. This vulnerability allows for remote exploitation, enabling unauthorized users to execute actions on admin models via POST requests. The problem has been publicly disclosed, but the project maintainers have not yet addressed it.

4.8
Jul 19, 2026

Gerapy Missing Authentication Vulnerability in Project Upload Endpoint

A vulnerability allowing unauthenticated file uploads has been identified in Gerapy versions through 0.9.13. The issue resides in the project upload endpoint, where the authentication requirement has been disabled. This flaw can be exploited remotely, allowing attackers to upload arbitrary ZIP files, which are then extracted into the projects directory on the server.

5.9
Jul 19, 2026

django-tastypie Cache Throttle Race Condition Vulnerability

A race condition vulnerability has been identified in django-tastypie versions through 0.15.1. The issue arises in the CacheThrottle and CacheDBThrottle functions within tastypie/throttle.py. This vulnerability can be exploited remotely, although the complexity of the attack is considered high.

4.2
Jul 19, 2026

django-tastypie ApiKeyAuthentication Vulnerability Allowing Credential Exposure via URL Parameters

A vulnerability exists in django-tastypie versions through 0.15.1, specifically within the ApiKeyAuthentication function in authentication.py. This issue allows for the remote exploitation of GET or POST request methods to include sensitive query strings, such as API credentials. The vulnerability arises from the authentication method's acceptance of credentials via URL parameters when no Authorization header is provided, potentially leading to API key leakage.

5.2
Jul 19, 2026

Django OAuth Toolkit Session Expiration Vulnerability in ID Token Handling

A vulnerability in Django OAuth Toolkit version 3.3.0 allows for session expiration issues related to ID token management. The vulnerability arises in the '_load_id_token' function within 'oauth2_provider/oauth2_validators.py', where expired ID tokens can be accepted during logout processes. This issue can be exploited remotely, leading to unintended session terminations.

3.4
Jul 19, 2026

Pluck CMS Stored Cross-Site Scripting Vulnerability in Albums Module

A stored cross-site scripting vulnerability has been identified in Pluck CMS versions through 4.7.21. The issue resides in the Albums Module, specifically within the 'data/modules/albums/albums.admin.php' file. The vulnerability arises because user input in the image description field is not properly sanitized before being displayed on the frontend, allowing for the injection of malicious JavaScript. This vulnerability can be exploited remotely, and the injected script is executed in the context of the user viewing the affected album.

4.7
Jul 19, 2026

Zevorn RT-Claw Remote Code Execution Vulnerability in Telegram-to-AI Tool Integration

A remote code execution vulnerability has been identified in Zevorn RT-Claw versions prior to 0.2.0. The issue arises in the Telegram-to-AI tool execution flow, specifically within the 'tool_run_script_execute' function of 'claw/services/tools/script.c'. This vulnerability allows for code injection by manipulating the 'message.text' received from Telegram, which is processed by the AI engine and executed as Python code on the Linux platform, without any user confirmation or approval. The exploit has been made public and can be used to execute arbitrary Python scripts with the permissions of the RT-Claw process, potentially leading to unauthorized access to files, credentials, and other system resources.

4.7
Jul 19, 2026

SourceCodester Class and Exam Timetabling System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The issue arises in the file '/forCYS.php', where the 'course' parameter is not properly validated or encoded before being output to the web page. This flaw allows remote attackers to inject malicious scripts that could be executed in the context of the user's browser, potentially leading to the theft of cookies, session tokens, or other sensitive information.

4.2
Jul 19, 2026

SourceCodester Class and Exam Timetabling System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The issue arises in the file '/CYS.php', where the 'course' parameter is not properly validated or encoded, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, with the injected scripts executed in the context of the user's browser.

4.2
Jul 19, 2026

Zevorn RT-Claw Information Disclosure Vulnerability in HTTP Request Tool

An information disclosure vulnerability has been identified in Zevorn RT-Claw versions through 0.2.0. The issue arises in the HTTP request handling functions within the 'claw/services/tools/net.c' file. The vulnerability allows remote attackers to manipulate tool arguments and access local files through the 'file://' URL scheme, which is not properly validated before being sent to libcurl. This flaw could expose sensitive information such as configuration files, logs, API tokens, or other readable files depending on the service account's permissions.

4.7
Jul 19, 2026

Zevorn RT-Claw Incorrect Authorization Vulnerability in Swarm RPC Handler Allowing Arbitrary Code Execution

An incorrect authorization vulnerability has been identified in Zevorn RT-Claw versions through 0.2.0. The issue resides in the RPC Handler component, specifically within the claw_tool_invoke function of the file claw/services/swarm/swarm.c. This vulnerability allows for unauthorized execution of tools marked as local-only, bypassing intended security restrictions. The flaw can be exploited remotely, leading to unauthorized execution of arbitrary Python code on Linux nodes where the 'run_script' tool is enabled.

4.7
Jul 19, 2026

Nextlevelbuilder GoClaw Improper Authorization Vulnerability in Exec Tool

A vulnerability allowing improper authorization has been identified in Nextlevelbuilder GoClaw versions up to 3.13.3-beta.3. The issue arises in the ExecTool.Execute function within the file goclaw/internal/tools/credentialed_exec.go. This vulnerability can be exploited remotely by authenticated users with operator-level roles, allowing them to execute registered high-risk command-line interfaces (CLIs) without the necessary permissions. The bypass is achieved by wrapping commands in PowerShell encoded-command syntax, evading the application's authorization checks.

4.0
Jul 19, 2026

Sipeed PicoClaw Authentication Bypass Vulnerability via Same-Host Loopback Proxying

An authentication bypass vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9. The issue arises in the First Run Setup component, specifically within the web/backend/middleware/access_control.go file. The vulnerability allows remote attackers to bypass authentication by manipulating the 'allowed_cidrs' argument, exploiting the application's trust in loopback IPs. This flaw enables unauthorized access to the launcher dashboard's administrative features, particularly during the initial setup phase when no password has been established.

4.6
Jul 18, 2026

Sipeed PicoClaw Missing Authorization Vulnerability in Feishu Group Message Handler

A vulnerability allowing for missing authorization has been identified in Sipeed PicoClaw versions through 0.2.9. The issue arises in the Group Message Handler, specifically within the handleMessageReceive function of the feishu_64.go file. This vulnerability can be exploited remotely, allowing an attacker to manipulate message context and bypass authorization checks.

4.2
Jul 18, 2026

Sipeed PicoClaw Server-Side Request Forgery Vulnerability in Web Fetch Component

A server-side request forgery (SSRF) vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9. The issue resides in the 'isPrivateOrRestrictedIP' function within 'pkg/tools/integration/web.go', specifically in the 'web_fetch' component. The vulnerability arises because the IP restriction logic fails to block special-use IPv4 addresses, such as '198.18.0.0/15', which should be considered restricted. This oversight allows an attacker to bypass the application's network egress policy and access internal resources via the 'web_fetch' tool.

4.1
Jul 18, 2026

Sipeed PicoClaw WeCom Group Message Handler Authorization Bypass Vulnerability

An authorization bypass vulnerability has been identified in Sipeed PicoClaw versions through 0.2.9, specifically within the WeCom group message handling component. The issue arises in the 'dispatchIncoming' function of 'wecom.go', where the application fails to properly enforce group trigger policies. This flaw allows unmentioned group messages to be processed by the PicoClaw agent, contradicting the intended 'mention-only' requirement. The vulnerability can be exploited remotely, and the published exploit may be used for attacks.

4.3
Jul 18, 2026

QueryWeaver Authentication Bypass Vulnerability Allowing Session Token Issuance for Existing Accounts

An authentication bypass vulnerability has been identified in QueryWeaver versions through 0.2.0. This vulnerability allows unauthenticated attackers to obtain valid session tokens for existing accounts by sending a signup request with a known victim email address. The issue arises because the signup route creates and links a new token to the corresponding identity before verifying if the email is associated with an existing account. As a result, the server inadvertently returns a valid authenticated session token for the victim's identity, without requiring any prior credentials or user interaction.

4.2
Jul 18, 2026

zhayujie CowAgent Server-Side Request Forgery Vulnerability in Web Fetch Tool

A server-side request forgery (SSRF) vulnerability has been identified in zhayujie CowAgent versions through 2.1.1. The issue resides in the WebFetch tool, specifically within the execute function of web_fetch.py. The vulnerability allows for manipulation of the 'url' argument, enabling requests to internal or special-use HTTP destinations. This flaw can be exploited remotely, potentially leading to unauthorized access to internal services or metadata endpoints. The vulnerability has been publicly disclosed and exploited, but has been patched in version 2.1.2.

4.5
Jul 18, 2026

SourceCodester Class and Exam Timetabling System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The issue resides in the '/forexam.php' file, where the 'day' parameter is not properly validated or encoded, allowing remote attackers to inject and execute malicious scripts in the context of the user's browser. This vulnerability could be exploited to steal cookies, session tokens, or other sensitive information, perform actions on behalf of the user, deface web pages, redirect users to malicious sites, or gain control of the user's browser.

4.2
Jul 18, 2026

Flow Payment Plugin for WordPress Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Flow Payment plugin for WordPress, specifically in version 3.0.8. The issue occurs on the WooCommerce checkout page, where the plugin improperly handles the error_message GET parameter during order cancellations. This parameter is passed directly to the wc_add_notice() function without adequate input sanitization or output escaping, leaving it vulnerable to JavaScript payloads. An unauthenticated attacker can exploit this by crafting a URL with a malicious payload in the error_message parameter. When a victim with an active WooCommerce checkout session clicks the link, the payload executes in their browser, originating from the WordPress site.

2.7
Jul 18, 2026

SourceCodester Class and Exam Timetabling System Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The issue arises in the file '/schoolyr.php', where the 'sy' parameter is not properly validated or encoded, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, with public proof-of-concept available.

4.2
Jul 18, 2026

SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, specifically in version 1.0. The issue arises in the file '/edit_room1.php', where the 'id' parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely, without any authentication.

4.7
Jul 18, 2026

SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability in edit_rooma.php

A SQL injection vulnerability exists in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the edit_rooma.php file. The vulnerability arises from inadequate validation of the 'id' parameter, allowing remote attackers to inject malicious SQL queries. This exploitation could lead to unauthorized database access, data manipulation, and leakage of sensitive information.

4.7
Jul 18, 2026

parisneo Lollms Stored Cross-Site Scripting Vulnerability in Prompt Sharing

A stored cross-site scripting vulnerability has been identified in the latest version of parisneo Lollms, specifically within the POST /api/prompts/share endpoint. This vulnerability arises because the endpoint allows attacker-controlled prompt content to be stored in the DBDirectMessage.content field without any server-side sanitization. When a victim accesses the direct message thread, the content is rendered by the DM user interface using MessageContentRenderer, which employs v-html to insert HTML into the DOM. The frontend sanitizer, based on regular expressions, fails to adequately cleanse attacker-controlled HTML, permitting malicious payloads to execute in the context of the victim's browser. As a result, any authenticated user can send a harmful prompt-sharing message to another user's inbox, leading to the execution of arbitrary JavaScript, authenticated actions on behalf of the victim, exposure of same-origin application data, and potential account takeover.

3.8
Jul 18, 2026

Stoat for Android Improper URI Validation in Exported ShareTargetActivity Component Leading to Internal File Disclosure

A vulnerability in Stoat for Android versions prior to 1.6.0 allows for improper validation of URIs in an exported activity. The ShareTargetActivity component, accessible to any process on the device via the SEND intent, accepts file URIs pointing to the application's internal storage, such as databases, cached authentication tokens, or preferences. This lack of validation enables an attacker to exploit the activity, causing the victim to unintentionally share sensitive internal files as attachments in Stoat channels or with specific users. The shared files could include the local Stoat database, authentication tokens for account takeover, or any other file readable by the app process.

3.3
Jul 18, 2026

ProFTPD Heap-Based Buffer Overflow Vulnerability in SFTP Module Allowing Denial-of-Service

A heap-based buffer overflow vulnerability has been identified in the ProFTPD SFTP module (mod_sftp) versions prior to 1.3.10. This vulnerability is accessible to authenticated SFTP users and is caused by the fxp_packet_read() function, which improperly handles the 32-bit big-endian SFTP packet length. The lack of a minimum sanity check allows an attacker to craft a packet that triggers an unsigned integer underflow, leading to a request size of approximately 4 GB. This oversized request is mismanaged by the memory allocator, causing a small block to be allocated while the caller is misled into believing a much larger size was received. Exploitation involves sending a malformed SFTP packet with a length of 0, followed by a body exceeding 544 bytes, which results in a controlled buffer overflow on the heap.

6.1
Jul 18, 2026

CartoDB Carto-Api-Client Prototype Pollution Vulnerability in AddFilter Function

A prototype pollution vulnerability has been identified in CartoDB's carto-api-client version 0.5.29. The issue arises in the addFilter function within src/filters.ts, where improper handling of the column argument allows for unauthorized modification of object prototype properties. This vulnerability can be exploited remotely.

4.7
Jul 18, 2026

RobinHerbots Inputmask Prototype Pollution Vulnerability in Internal Deep Merge Helper

A prototype pollution vulnerability has been identified in RobinHerbots Inputmask versions through 5.0.9. The issue arises in the internal deep merge helper function, which is part of the library's dependency management. The vulnerability allows for uncontrolled modification of object prototype attributes, potentially leading to malicious exploitation from remote sources.

4.7
Jul 18, 2026

LiuMengxuan04 MiniCode Command Injection Vulnerability

A command injection vulnerability has been identified in LiuMengxuan04 MiniCode version 0.1.0. The issue arises in the 'mcp.ts' file, specifically within the 'child_process.spawn' function. This vulnerability allows for remote code execution by injecting malicious commands that are executed in the context of the user's environment. Exploitation of this vulnerability is complex and appears to be challenging, but a proof-of-concept exploit has been published and could be used.

3.7
Jul 18, 2026

itsourcecode Hospital Management System SQL Injection Vulnerability in prescriptionrecord.php

A SQL injection vulnerability has been identified in the itsourcecode Hospital Management System version 1.0. The issue resides in the prescriptionrecord.php file, where the delid parameter is not properly sanitized, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, potentially leading to unauthorized database access, data manipulation, and disruption of service.

3.9
Jul 18, 2026

NearAI IronClaw Symlink Vulnerability in Write File Tool Allows Arbitrary File Writes

A vulnerability in NearAI IronClaw versions through 0.29.1 allows the built-in 'write_file' tool to write files outside of its designated sandbox. This occurs when the specified path is a dangling symlink pointing to a location beyond the sandbox boundary. The path validation process fails to resolve the symlink correctly, leading to an unauthorized write. The issue requires local access to exploit and has a public exploit available.

3.3
Jul 18, 2026

princezuda SafestClaw Shell Command Allowlist Bypass Vulnerability

A command-execution policy bypass vulnerability has been identified in princezuda SafestClaw versions through 4.2.4. The issue resides in the built-in web interface's shell action, specifically within the command validation function. The vulnerability allows local execution of denied commands by exploiting an incomplete allowlist. When a command is sent through the web interface, the parser extracts it and forwards it to the shell action without proper validation of the effective executable. This oversight enables the invocation of blocked interpreters, such as bash, by wrapping them in approved commands like 'env'. As a result, the bypassed command executes with the same privileges as the SafestClaw process, potentially accessing sensitive files, environment variables, and network resources.

3.4
Jul 18, 2026

Zevorn RT-Claw Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Zevorn RT-Claw versions through 0.2.0. The issue resides in the 'receiver_thread' function within 'claw/services/swarm/swarm.c', specifically related to the 'http_request' component. This vulnerability allows remote attackers to manipulate requests that the server processes, potentially accessing internal resources or loopback addresses.

4.5
Jul 18, 2026

Zevorn RT-Claw Server-Side Request Forgery Vulnerability in HTTP Request Tool

A server-side request forgery (SSRF) vulnerability has been identified in Zevorn RT-Claw versions through 0.2.0. The issue arises in the 'http_request' tool, specifically within the 'claw/tools/tool_net.c' file. The vulnerability allows remote attackers to manipulate the 'url' argument, leading to unauthorized HTTP requests being sent to internal or private network addresses. This could expose sensitive information from loopback or private services.

4.5
Jul 18, 2026

Zevorn rt-claw Swarm RPC Receiver Incorrect Authorization Vulnerability

An authorization bypass vulnerability has been identified in the Zevorn rt-claw application, specifically in versions up to 0.2.0. The issue resides in the Swarm RPC Receiver component, within the handle_rpc_request function of the file claw/services/swarm/swarm.c. This vulnerability allows remote invocation of tools marked as local-only, bypassing intended authorization checks. The flaw has been publicly disclosed and is present in unreleased commits after v0.2.0, including the verified vulnerable commit 36d128f72afa0b9d40a21bcd6069b0c193a58f82.

4.8
Jul 18, 2026

Zevorn rt-claw Server-Side Request Forgery Vulnerability in http_request Tool

A server-side request forgery (SSRF) vulnerability has been identified in Zevorn rt-claw versions through 0.2.0. The issue arises in the http_request component, specifically within the claw_net_get and claw_net_post functions in claw/services/tools/net.c. The vulnerability allows for arbitrary outbound HTTP requests to be made to internal or localhost resources, with the response being returned to the user. This exploitation can be performed remotely, and the vulnerability has been publicly disclosed.

4.5
Jul 18, 2026

nextlevelbuilder GoClaw Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in nextlevelbuilder GoClaw versions through 3.15.0-beta.32. The issue arises in the web_fetch component, specifically within the CheckSSRF/isPrivateIP function of the file internal/tools/web_shared.go. This vulnerability allows authenticated users with at least operator privileges to bypass SSRF protections and make requests to internal or special-use IP ranges that should be blocked. The flaw has been publicly disclosed and exploited, but it has been patched in version 3.15.0-beta.33.

3.7
Jul 18, 2026

nextlevelbuilder GoClaw Missing Authorization Vulnerability in Tools Invoke Endpoint Allows Unauthorized Cron Job Binding

A vulnerability exists in nextlevelbuilder GoClaw versions through 3.13.2, specifically within the ToolsInvokeHandler.ServeHTTP function of the internal/http/tools_invoke.go file. This vulnerability arises from a missing authorization check in the Invoke Endpoint, allowing an authenticated user with operator.write privileges to bind a cron job to another user's private agent. While direct access to the foreign agent is correctly blocked, the cron binding is accepted without proper authorization, creating a stored cross-agent authorization bypass that the scheduler later trusts as the execution target.

3.9
Jul 18, 2026

Nextlevelbuilder GoClaw Authorization Bypass Vulnerability in Exec Approval

An authorization bypass vulnerability has been identified in Nextlevelbuilder GoClaw versions up to 3.13.2. The issue arises in the exec approval process, where the system incorrectly treats different executables as the same trusted binary if they share a basename. This flaw allows an authenticated operator-level user to execute commands on the host without proper authorization, bypassing the intended approval process.

4.1
Jul 18, 2026

Nextlevelbuilder GoClaw Improper Authorization Vulnerability in Exec Approval Tool

A vulnerability exists in Nextlevelbuilder GoClaw versions up to 3.13.2, specifically within the exec approval tool. The issue arises from the 'isSafeBin' function in 'internal/tools/exec_approval.go', which improperly classifies certain commands as safe based solely on their binary name. This flaw allows authenticated users with operator privileges to execute commands that read from or write to the filesystem without the required human approval. The vulnerability can be exploited remotely, and public exploit scripts are available.

3.9
Jul 18, 2026

Urwid Web Display Backend Session ID Vulnerability Allowing Keystroke Injection and Code Execution

A vulnerability exists in the Urwid web display backend, specifically in the session ID generation process. The backend uses Python's Mersenne Twister pseudo-random number generator (PRNG) to create web session identifiers. This PRNG is not cryptographically secure, allowing an attacker to predict session IDs. The vulnerability arises because each session ID is generated by concatenating two random numbers from the PRNG, which can be observed through the X-Urwid-ID HTTP response header. An attacker who collects approximately 334 session IDs can reconstruct the internal state of the PRNG and predict all past and future session IDs. Additionally, the session ID is used as the filename for a FIFO (named pipe) created in the world-readable /tmp directory. This exposure allows any local user to enumerate active session tokens directly. With a valid session ID, an attacker can read the victim's terminal screen, inject keystrokes (potentially leading to OS-level code execution if the session runs a shell), and disrupt the session by flooding the FIFO or injecting exit sequences.

4.4
Jul 18, 2026

Nextlevelbuilder GoClaw Incorrectly-Resolved Name Vulnerability in Exec Approval Allowlist

A vulnerability exists in Nextlevelbuilder GoClaw versions up to 3.13.3-beta.3, specifically within the exec approval management. The issue arises because the 'matchesAllowlist' function trusts basename-only entries, allowing operators to manipulate and execute commands that bypass the intended approval process. This vulnerability can be exploited remotely by authenticated operators via the 'POST /v1/tools/invoke' HTTP endpoint.

4.1
Jul 18, 2026

GoClaw WebSocket Approval Endpoint Incorrect Authorization Vulnerability

A vulnerability exists in GoClaw versions up to 3.13.2, specifically within the WebSocket approval endpoint. The issue arises in the 'RequestApproval' function of 'internal/tools/exec_approval.go', where the approval cache incorrectly handles 'allow-always' decisions. This flaw allows an operator to approve one BusyBox-wrapped command, which can then be exploited to execute different commands without additional approval, bypassing GoClaw's intended authorization process for executing host commands.

3.9
Jul 18, 2026

@fastify/http-proxy Prefix Escape Vulnerability via URL-Encoding

A vulnerability exists in @fastify/http-proxy versions through 11.5.0, where the request prefix is not properly rewritten if the prefix segment contains URL-encoded characters. Fastify's routing system decodes URLs for matching purposes, but the original encoded request.url is forwarded to the upstream server without modification. This allows an attacker to access upstream paths that should be hidden by the prefix rewrite, potentially exposing internal or administrative endpoints. The issue arises because the prefix rewrite process uses a literal string replacement, which fails to account for URL encoding.

5.7
Jul 18, 2026

OpenPLC Runtime v3 Heap-Based Buffer Overflow Vulnerability in Modbus Master Component

A heap-based buffer overflow vulnerability has been identified in OpenPLC Runtime v3, specifically in the Modbus Master component. The issue arises in the getData() function within webserver/core/modbus_master.cpp, where the function reads data into a user-supplied buffer without proper size validation or bounds checking. This vulnerability affects all versions of OpenPLC Runtime v3 up to the latest master commit (b470206). An authenticated attacker with access to the OpenPLC web interface can exploit this vulnerability by sending a crafted HTTP POST request to the /modbus endpoint, using an oversized device_name value. The overflow occurs as the value is saved to mbconfig.cfg and parsed upon loading, overwriting adjacent struct fields and causing heap corruption. This heap corruption leads to a runtime crash, disrupting the PLC process control loop and causing a denial-of-service condition.

4.1
Jul 18, 2026

SurrealDB HTTP Redirect Vulnerability Allowing Server-Side Request Forgery

A server-side request forgery (SSRF) vulnerability has been identified in SurrealDB versions prior to 2.2.2. The issue arises because the database fails to properly validate HTTP redirects in its HTTP functions. This flaw enables authenticated users to circumvent deny-net restrictions by redirecting to blocked IP addresses. Attackers can exploit this by hosting a public server that redirects to denied network targets, thereby accessing internal endpoints and potentially retrieving sensitive information.

2.4
Jul 18, 2026

SurrealDB Denial-of-Service Vulnerability via CPU Exhaustion from Nested FOR Loops

A denial-of-service vulnerability has been identified in SurrealDB versions prior to 2.0.5, 2.1.x prior to 2.1.5, and 2.2.x prior to 2.2.2. This vulnerability allows authenticated users with OWNER or EDITOR permissions at the root, namespace, or database level to create custom database functions using the DEFINE FUNCTION statement. The issue arises from the ability to nest FOR loops, each capable of iterating up to 1,000,000 times. While a single loop's iterations are limited, nesting multiple loops can lead to functions that consume excessive CPU resources. This unchecked execution monopolizes server processing, causing the database to become unresponsive to other queries and connections until it is manually restarted.

2.4
Jul 18, 2026

SurrealDB Denial-of-Service Vulnerability via Unrestricted JavaScript Execution Time

A denial-of-service vulnerability has been identified in SurrealDB versions prior to 2.0.5, 2.1.x prior to 2.1.5, and 2.2.x prior to 2.2.2. The issue arises because these versions do not impose a default execution-time limit on embedded JavaScript functions when scripting is enabled. This lack of restriction allows authenticated attackers to submit long-running scripts that can exhaust server resources, leading to a denial-of-service condition. Scripting is disabled by default, but can be enabled with specific command-line flags or environment variables.

2.6
Jul 18, 2026

SurrealDB Memory Exhaustion Vulnerability in String Replace Function Prior to 2.2.2

A memory exhaustion vulnerability has been identified in SurrealDB versions prior to 2.2.2. This issue arises in the string::replace function, which fails to limit the length of resulting strings when regex patterns are used. An authenticated attacker can exploit this by crafting a malicious query that leads to unbounded string allocations, exhausting server memory and causing a denial-of-service condition.

2.6
Jul 18, 2026

SurrealDB Local File Read Vulnerability in DEFINE ANALYZER Statement

A local file read vulnerability has been identified in SurrealDB versions prior to 2.2.2. This issue allows authenticated users with root, namespace, or database level privileges to use the DEFINE ANALYZER statement to access arbitrary files on the file system. The vulnerability specifically targets two-column tab-separated values (TSV) files, which can be read and exfiltrated by the attacker.

2.4