PT-2026-61553 · Surrealdb · Surrealdb
CVE-2026-63737
·
Published
2026-07-20
·
Updated
2026-07-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SurrealDB versions prior to 3.1.5
Description
Authenticated users can cause a denial of service by submitting queries containing long chains of operators. This occurs when tens of thousands of chained operators create unbounded expression trees, leading to a stack overflow during query processing and causing the entire process to abort.
Recommendations
Update SurrealDB to version 3.1.5 or later.
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surrealdb