PT-2026-85339 · Crates.Io · Surrealdb

Published

2026-07-18

·

Updated

2026-07-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-3824-qmfq-2qv7. This link is maintained to preserve external references.

Original Description

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all). An authenticated attacker can submit long-running JavaScript functions to exhaust server resources and cause a denial of service. Scripting is disabled by default.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-6G9R-XQRF-34XH

Affected Products

Surrealdb