PT-2026-61550 · Surrealdb · Surrealdb
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SurrealDB versions prior to 3.2.0
Description
A denial of service issue exists in the SurrealML header parser. Authenticated users with the Owner role can crash the server by uploading a malformed .surml file to the '/ml/import' endpoint. By providing non-numeric
input-dimensions or other malformed header fields, attackers can trigger unchecked unwrap calls, leading to a panic that aborts the server process and denies service to all databases.Recommendations
Update SurrealDB to version 3.2.0 or later.
Restrict access to the '/ml/import' endpoint to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surrealdb