Denial of Service Vulnerability in SurrealDB by SurrealDB
CVE-2026-63759
7.1HIGH
What is CVE-2026-63759?
SurrealDB prior to version 3.1.0 is vulnerable to a Denial of Service attack due to inadequate enforcement of recursion depth limits in its type/kind parser. This flaw allows authenticated attackers to craft queries with excessively nested type annotations, leading to memory exhaustion and potential server crashes. Administrators should ensure they are on the latest version to mitigate this risk.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
