A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.
Metrics
Affected Vendors & Products
References
History
Sat, 27 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 26 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 26 Sep 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records. | |
Title | Surrealdb: surrealdb is vulnerable to unauthorized data exposure via live query subscriptions | |
First Time appeared |
Redhat
Redhat service Mesh |
|
Weaknesses | CWE-863 | |
CPEs | cpe:/a:redhat:service_mesh:3 | |
Vendors & Products |
Redhat
Redhat service Mesh |
|
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-09-26T13:04:11.588Z
Reserved: 2025-09-26T11:46:23.698Z
Link: CVE-2025-11060

Updated: 2025-09-26T13:04:08.951Z

Status : Awaiting Analysis
Published: 2025-09-26T13:15:41.757
Modified: 2025-09-26T14:32:19.853
Link: CVE-2025-11060
