PT-2026-61566 · Surrealdb · Surrealdb

CVE-2026-63750

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.1.0
Description Anonymous WebSocket connections to the '/sql' endpoint do not enforce the SURREAL WEBSOCKET MAX MESSAGE SIZE limit. This allows attackers to buffer unbounded frames in the per-connection read buffer by streaming frames that exceed the configured limit across multiple concurrent connections, leading to excessive memory consumption and degradation of '/sql' availability.
Recommendations Update SurrealDB to version 3.1.0 or later.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63750

Affected Products

Surrealdb