Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-63753

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Jul 20, 2026
Vendor unknown

Description

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

References