SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSurrealdb
APPSurrealdb3.0.0 – 3.1.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
Related vulnerabilities
CVE-2026-63756CRITICAL9.2PL ✓same product
SurrealDB: Race condition w /rpc umożliwia przejęcie sesji uwierzytelnionej
CVE-2025-71392CRITICAL9.4PL ✓same product
SurrealDB: injection SurrealQL przez eksport — privilege escalation
CVE-2024-58366CRITICAL9.0PL ✓same product
Format string vulnerability w SurrealDB — RCE przez scripting
CVE-2026-63739HIGH8.3PL ✓same product
SurrealDB: Odczyt dowolnych plików przez filtr DEFINE ANALYZER
CVE-2026-63735HIGH8.6PL ✓same product
SurrealDB — brak walidacji zakresu w niestandardowych trasach API