Denial of Service Vulnerability in SurrealDB by SurrealDB Inc.
CVE-2026-63760
8.7HIGH
What is CVE-2026-63760?
SurrealDB prior to version 3.1.0 contains a vulnerability that allows unauthorized users to exploit the value and JSON parser. By sending deeply nested JSON payloads to the /rpc WebSocket endpoint, attackers can bypass configured recursion depth limits, leading to excessive memory consumption and potentially crashing the server. This vulnerability poses a significant risk to server stability and service availability.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
