CVE 5.7 MEDIUM

Surrealdb: surrealdb is vulnerable to unauthorized data exposure via live query subscriptions_CVE-2025-11060

5.7 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Description

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.

Basic Information

ID CVE-2025-11060
Source redhat
Published Sep 26, 2025 at 12:01

Affected Product

Vendor Red Hat
Product OpenShift Service Mesh 3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.