Impact
The vulnerability occurs when the SurrealDB RPC use handler receives a malformed WebSocket message that sets a database without specifying a namespace. This causes the server process to panic and crash, resulting in a denial of service. The primary impact is loss of availability to all clients that rely on the impacted instance; no information disclosure or privilege escalation is reported.
Affected Systems
SurrealDB versions prior to 3.1.0 are affected. No specific patch versions are listed, so all builds before 3.1.0 should be considered vulnerable.
Risk and Exploitability
The CVSS score is 8.7. The EPSS score indicates a low probability of exploitation. Although the vulnerability does not require authentication, the low EPSS suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers could target the /rpc endpoint remotely via an unauthenticated WebSocket connection to trigger a server crash.
OpenCVE Enrichment