Denial of Service Vulnerability in SurrealDB by SurrealDB
CVE-2026-63734
6.9MEDIUM
What is CVE-2026-63734?
SurrealDB versions prior to 3.2.0 are susceptible to a denial of service issue caused by the SurrealML header parser. This vulnerability can be exploited by authenticated users with Owner-role privileges, allowing them to upload a malformed .surml file to the /ml/import endpoint. Attackers can input non-numeric dimensions or invalid header fields, leading to unchecked unwrap calls that trigger server panic, thereby causing the entire server process to abort. This results in a denial of service for all databases on the affected server.
Affected Version(s)
surrealdb 0 < 3.2.0
surrealdb 3.2.0
