Description
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the server and causing denial of service.
Published: 2026-07-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SurrealDB versions before 1.2.1 contain an uncaught exception when rendering spans during query parsing. Malformed queries that include line terminator errors trigger a panic in the server, causing it to crash. The result is a denial of service, exposing the service to downtime and potential operational impact. This flaw is classified as CWE‑248, an Uncaught Exception or Failure to Release Resource.

Affected Systems

The vulnerability affects all installations of SurrealDB prior to version 1.2.1. Clients with authorized access to the database – such as internal applications or services that submit queries over the network – can exploit the flaw. The impact is limited to the affected database instance, resulting in loss of availability for that instance.

Risk and Exploitability

The CVSS score of 7.1 indicates a high risk to availability. The EPSS score of less than 1 % shows a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The payload is delivered by an authorized client that can send malformed queries; therefore the attacker must have authenticated or privileged access to the SurrealDB service.

Generated by OpenCVE AI on July 30, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 1.2.1 or newer to incorporate the fix.
  • Limit database access to trusted clients and enforce strict query validation to reject malformed input before it reaches the parser.
  • Monitor server logs for panics and implement high‑availability or fail‑over mechanisms to reduce downtime if a crash occurs.

Generated by OpenCVE AI on July 30, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the server and causing denial of service.
Title SurrealDB before 1.2.1 Denial of Service via Parsing Error
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:47:51.243Z

Reserved: 2026-07-18T12:40:52.916Z

Link: CVE-2024-58364

cve-icon Vulnrichment

Updated: 2026-07-22T18:56:47.707Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses