PT-2026-60945 · Surrealdb · Surrealdb

·

CVE-2024-58365

·

Published

2024-02-21

·

Updated

2026-08-12

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.2.0
Description An uncaught exception exists in the query executor when processing calls to built-in functions that do not exist. Authorized clients can trigger a panic that crashes the server by crafting pre-parsed queries that invoke these nonexistent functions.
Recommendations Update SurrealDB to version 1.2.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58365
GHSA-6WR5-JMPR-MJCX
GHSA-9QJC-Q7HW-VW5R

Affected Products

Surrealdb