PT-2026-60948 · Surrealdb · Surrealdb

·

CVE-2024-58368

·

Published

2024-01-18

·

Updated

2026-07-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.1.0
Description An issue exists where the server fails to properly parse the ID, DB, and NS headers in HTTP REST API requests that contain special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger an uncaught exception, resulting in a denial of service by crashing the server.
Recommendations Update to version 1.1.0 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58368
GHSA-F7Q6-7RQ9-3PHX
GHSA-M24X-R6Q3-2VP9

Affected Products

Surrealdb