PT-2026-60944 · Surrealdb · Surrealdb

·

CVE-2024-58364

·

Published

2024-02-21

·

Updated

2026-08-12

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.2.1
Description An uncaught exception occurs during span rendering when the system parses queries containing errors on line terminator characters. Authorized clients can trigger a panic in the span rendering code by submitting malformed queries, which crashes the server and results in a denial of service.
Recommendations Update SurrealDB to version 1.2.1 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58364
GHSA-8XFF-473H-F863

Affected Products

Surrealdb