Description
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
Published: 2026-07-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SurrealDB versions prior to 1.1.1 contain a logic flaw that allows authorized clients to invoke custom parameters and functions at the root or namespace levels. When these invocations occur at unsupported levels, the server panics and crashes, resulting in a denial of service. The primary weakness is a failure to validate the scope of these invocations, which leads directly to a server crash. The impact is limited to availability, as the flaw does not expose data or modify it.

Affected Systems

The vulnerability affects SurrealDB products from the vendor surrealdb. All releases before 1.1.1 are affected. No specific minor patches are listed beyond the major version threshold, so any build older than 1.1.1 should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker have legitimate client credentials to send requests that invoke unsupported global parameters or functions, so legitimate authorization is a prerequisite. Given the low exploitation probability, the risk is mostly theoretical unless an attacker gains authorized access and intentionally triggers the crash.

Generated by OpenCVE AI on July 30, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 1.1.1 or later to remove the validation flaw.
  • Ensure that only authorized clients are allowed to invoke global functions or parameters, and consider disabling or restricting these capabilities if not needed.
  • Monitor server logs for unexpected panics or crashes and verify that all clients are compliant with the updated validation rules.

Generated by OpenCVE AI on July 30, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb

Mon, 20 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
Title SurrealDB before 1.1.1 Denial of Service via Global Parameters
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:47:54.726Z

Reserved: 2026-07-18T12:40:52.917Z

Link: CVE-2024-58369

cve-icon Vulnrichment

Updated: 2026-07-20T19:23:36.926Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses