Impact
SurrealDB versions before 1.2.1 contain an uncaught exception when rendering spans during query parsing. Malformed queries that include line terminator errors trigger a panic in the server, causing it to crash. The result is a denial of service, exposing the service to downtime and potential operational impact. This flaw is classified as CWE‑248, an Uncaught Exception or Failure to Release Resource.
Affected Systems
The vulnerability affects all installations of SurrealDB prior to version 1.2.1. Clients with authorized access to the database – such as internal applications or services that submit queries over the network – can exploit the flaw. The impact is limited to the affected database instance, resulting in loss of availability for that instance.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk to availability. The EPSS score of less than 1 % shows a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The payload is delivered by an authorized client that can send malformed queries; therefore the attacker must have authenticated or privileged access to the SurrealDB service.
OpenCVE Enrichment