Disclosure summary
SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x) has no ES512 variant and the mapping defaults to ES384 without any error, warning, or log message. Users who supply the correct P-521 key for ES512 experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384), and tokens are rejected by external systems expecting genuine ES512 signatures. The flaw cannot be used to forge tokens or compromise data confidentiality or integrity, as ES384 remains cryptographically strong.
Source-reported weakness categories
CWE-327
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-63761
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| surrealdb | surrealdb | * {"versionEndExcluding":"3.1.0"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Mitigation, Vendor Advisory
- www.vulncheck.com — Third Party Advisory
PUBLISHED 2026-07-20T08:19:46-04:00
MODIFIED 2026-10-08T12:17:28-04:00
INGESTED 2026-10-10T20:50:36-04:00