PT-2026-57511 · Crates.Io · Surrealdb

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The SurrealDB type/kind parser did not enforce the configured recursion depth limit when parsing nested type annotations. The expression parser already enforced the limit for analogous constructs; the kind parser omitted it. An authenticated attacker could send a query with deeply nested type annotations (e.g., array<option<array<option<...>>>>) and exhaust server memory, crashing the process.
This is an incomplete fix for GHSA-6r8p-hpg7-825g, which addressed the same class of bug in the expression parser but did not cover the kind/type annotation parser code path.

Impact

An authenticated user with query execution privileges can crash a SurrealDB server with a single WebSocket message containing deeply nested type annotations.

Patches

A patch has been introduced that wraps parse concrete kind and the OPTION<...> arm of parse inner kind with enter object recursion!, bounding the recursive cycle parse concrete kind → parse inner kind → parse inner single kind → parse concrete kind at the configured object recursion limit (default 100). Regression tests cover both cast and DEFINE FIELD paths.
  • Versions 3.1.0 and later are not affected by this issue.

Workarounds

Restrict the ability of untrusted users to execute arbitrary queries via the --deny-arbitrary-query capability flag for the affected user classes (guest, record, or system). Disabling untrusted access to the WebSocket /rpc endpoint also prevents exploitation; the HTTP /sql endpoint's 1 MiB body limit constrains nesting to a depth where OOM is not feasible.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-Q8QP-67F9-WR3F

Affected Products

Surrealdb