Memory Amplification Vulnerability in SurrealDB by SurrealDB
CVE-2026-63750
6.9MEDIUM
What is CVE-2026-63750?
Earlier versions of SurrealDB, prior to 3.1.0, have a vulnerability that fails to enforce the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit on anonymous /sql WebSocket connections. This flaw allows attackers to send excessively large WebSocket frames through multiple concurrent connections, potentially consuming excessive server memory and disrupting /sql availability. This could lead to performance degradation or a denial-of-service condition on the affected systems.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
