PT-2026-61550 · Surrealdb · Surrealdb

·

CVE-2026-63734

·

Published

2026-07-20

·

Updated

2026-07-22

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.2.0
Description A denial of service issue exists in the SurrealML header parser. Authenticated users with the Owner role can crash the server by uploading a malformed .surml file to the '/ml/import' endpoint. By providing non-numeric input-dimensions or other malformed header fields, attackers can trigger unchecked unwrap calls, leading to a panic that aborts the server process and denies service to all databases.
Recommendations Update SurrealDB to version 3.2.0 or later. Restrict access to the '/ml/import' endpoint to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63734

Affected Products

Surrealdb