Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmh9-9m2w-q5p4

Опубликовано: 20 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.

EPSS

Процентиль: 19%
0.0027
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
nvd
23 дня назад

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.

EPSS

Процентиль: 19%
0.0027
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-362