GHSA-2f98-6626-h2p2

Suggest an improvement
Source
https://github.com/advisories/GHSA-2f98-6626-h2p2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-2f98-6626-h2p2/GHSA-2f98-6626-h2p2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2f98-6626-h2p2
Withdrawn
2026-09-03T20:07:53Z
Published
2026-07-17T18:31:27Z
Modified
2026-09-03T20:15:05Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-h4h3-3rfj-x6fq. This link is maintained to preserve external references.

Original Description

SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field values. Attackers can issue ORDER BY queries on indexed restricted fields to recover the hidden values' sort order across records, even though the field itself returns null as intended.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-03T20:07:53Z",
    "nvd_published_at": "2026-07-17T17:17:17Z",
    "severity": "MODERATE"
}
References

Affected packages

crates.io / surrealdb

Package

Name
surrealdb
View open source insights on deps.dev
Purl
pkg:cargo/surrealdb

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0

Database specific

last_known_affected_version_range
"< 3.1.5"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-2f98-6626-h2p2/GHSA-2f98-6626-h2p2.json"