PT-2026-60939 · Surrealdb · Surrealdb

·

CVE-2024-58358

·

Published

2024-11-22

·

Updated

2026-07-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 2.1.0
Description A denial of service issue exists in role conversion. Privileged owner users can define users with nonexistent roles, which allows an attacker to trigger an uncaught panic—a critical error that causes the program to terminate—by signing in with a user assigned an invalid role, resulting in a server crash.
Recommendations Update SurrealDB to version 2.1.0 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58358
GHSA-9QRF-6WHP-92W3
GHSA-JC55-246C-R88F

Affected Products

Surrealdb