SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the server.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSurrealdb
APPSurrealdb< 1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2026-63756CRITICAL9.2PL ✓same product
SurrealDB: Race condition w /rpc umożliwia przejęcie sesji uwierzytelnionej
CVE-2025-71392CRITICAL9.4PL ✓same product
SurrealDB: injection SurrealQL przez eksport — privilege escalation
CVE-2024-58366CRITICAL9.0PL ✓same product
Format string vulnerability w SurrealDB — RCE przez scripting
CVE-2026-63737HIGH7.1PL ✓same product
SurrealDB — DoS poprzez przepełnienie stosu wywołaniami łańcuchów operatorów
CVE-2026-63735HIGH8.6PL ✓same product
SurrealDB — brak walidacji zakresu w niestandardowych trasach API