GHSA-p7hp-79jj-q923

Suggest an improvement
Source
https://github.com/advisories/GHSA-p7hp-79jj-q923
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p7hp-79jj-q923/GHSA-p7hp-79jj-q923.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p7hp-79jj-q923
Withdrawn
2026-09-04T20:07:31Z
Published
2026-07-20T12:33:09Z
Modified
2026-09-04T20:15:06Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6g9v-7gq3-p2c6. This link is maintained to preserve external references.

Original Description

SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.

Database specific
{
    "cwe_ids":  [
        "CWE-209"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-04T20:07:31Z",
    "nvd_published_at":  "2026-07-20T12:19:44Z",
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / surrealdb

Package

Name
surrealdb
View open source insights on deps.dev
Purl
pkg:cargo/surrealdb

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

last_known_affected_version_range
"< 3.1.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p7hp-79jj-q923/GHSA-p7hp-79jj-q923.json"