HIGH🇵🇱 Wersja polska

CVE-2024-58368

CVSS 8.7v4.0pub. 2026-07-18upd. 2026-08-13

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception that crashes the server.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Surrealdb

    APP
    Surrealdb
    < 1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-63756CRITICAL9.2PL ✓same product

SurrealDB: Race condition w /rpc umożliwia przejęcie sesji uwierzytelnionej

CVE-2025-71392CRITICAL9.4PL ✓same product

SurrealDB: injection SurrealQL przez eksport — privilege escalation

CVE-2024-58366CRITICAL9.0PL ✓same product

Format string vulnerability w SurrealDB — RCE przez scripting

CVE-2026-63737HIGH7.1PL ✓same product

SurrealDB — DoS poprzez przepełnienie stosu wywołaniami łańcuchów operatorów

CVE-2026-63735HIGH8.6PL ✓same product

SurrealDB — brak walidacji zakresu w niestandardowych trasach API