⚠ Withdrawn by GitHub Security Advisories

Withdrawn: September 4, 2026

GHSA-9qrf-6whp-92w3MediumCVSS 4.9Disclosed before NVD

Duplicate Advisory: SurrealDB has an Uncaught Exception Handling Nonexistent Role

Published
July 18, 2026
Last Modified
September 4, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jc55-246c-r88f. This link is maintained to preserve external references.

Original Description

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.

🎯 Affected products1

  • rust/surrealdb:< 2.1.0

🔗 References (4)