PT-2026-61575 · Surrealdb · Surrealdb

·

CVE-2026-63759

·

Published

2026-07-20

·

Updated

2026-07-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.1.0
Description The type/kind parser does not enforce recursion depth limits when processing nested type annotations. This allows authenticated attackers to send queries containing deeply nested type annotations, leading to server memory exhaustion and causing the process to crash.
Recommendations Update to version 3.1.0 or later.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63759

Affected Products

Surrealdb