Impact
SurrealDB versions prior to 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allow authenticated users with OWNER or EDITOR rights to define custom functions using DEFINE FUNCTION. Although single loops are bounded, nesting multiple loops—each capable of up to one million iterations—enables an attacker to execute code that consumes all CPU time and renders the database server unresponsive until a manual restart, affecting only the availability of the service.
Affected Systems
All SurrealDB deployments running the affected releases where users with OWNER or EDITOR permissions can create custom functions are impacted. The vulnerable versions are any release before 2.0.5, any 2.1.x release prior to 2.1.5, and any 2.2.x release prior to 2.2.2.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, while an EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker who can authenticate with OWNER or EDITOR rights can trigger the denial of service remotely, as the execution bypasses configured timeouts and leaves the server idle until a restart.
OpenCVE Enrichment