Description
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server.
Published: 2026-07-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SurrealDB versions prior to 2.0.4 expose an uncaught exception when the parser handles empty string inputs in queries, triggering a panic that crashes the server. The effect is a denial of service, disrupting service availability for all users. This weakness maps to CWE-248, an unhandled exception vulnerability.

Affected Systems

SurrealDB, versions before 2.0.4. All instances of the database running any of the pre‑2.0.4 releases are susceptible; the remediation is to apply the 2.0.4 update or later.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity. With an EPSS of less than 1%, the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authorized client to send malformed queries that convert empty strings to record, duration, or datetime types. Attackers with such credentials could trigger server crashes, but the impact is confined to service availability rather than data compromise.

Generated by OpenCVE AI on July 30, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 2.0.4 or later.
  • Configure client applications to reject or sanitize empty string conversions to record, duration, or datetime types until the database is updated.
  • Monitor system logs for panic or crash entries and set alerts for unexpected process terminations.

Generated by OpenCVE AI on July 30, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb

Tue, 21 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to record, duration, or datetime types that cause a panic in error rendering, crashing the server.
Title SurrealDB before 2.0.4 Denial of Service via Parser Exception
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:47:49.210Z

Reserved: 2026-07-18T12:40:52.916Z

Link: CVE-2024-58361

cve-icon Vulnrichment

Updated: 2026-07-21T02:35:53.721Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses