PT-2026-60941 · Surrealdb · Surrealdb

CVE-2024-58361

·

Published

2024-10-08

·

Updated

2026-07-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 2.0.4
Description An uncaught exception handling issue exists in the parser error rendering code when processing empty strings. Authorized clients can trigger a server crash by executing malformed queries that attempt to convert empty strings to record, duration, or datetime types, leading to a panic during error rendering.
Recommendations Update SurrealDB to version 2.0.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58361
GHSA-QJRV-V6QP-X99X

Affected Products

Surrealdb