Denial of Service Vulnerability in SurrealDB by SurrealDB
CVE-2026-63759

7.1HIGH

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63759?

SurrealDB prior to version 3.1.0 is vulnerable to a Denial of Service attack due to inadequate enforcement of recursion depth limits in its type/kind parser. This flaw allows authenticated attackers to craft queries with excessively nested type annotations, leading to memory exhaustion and potential server crashes. Administrators should ensure they are on the latest version to mitigate this risk.

Affected Version(s)

surrealdb 0 < 3.1.0

surrealdb 3.1.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DarkaMaul
.