Description
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.
Published: 2026-07-20
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs when the SurrealDB RPC use handler receives a malformed WebSocket message that sets a database without specifying a namespace. This causes the server process to panic and crash, resulting in a denial of service. The primary impact is loss of availability to all clients that rely on the impacted instance; no information disclosure or privilege escalation is reported.

Affected Systems

SurrealDB versions prior to 3.1.0 are affected. No specific patch versions are listed, so all builds before 3.1.0 should be considered vulnerable.

Risk and Exploitability

The CVSS score is 8.7. The EPSS score indicates a low probability of exploitation. Although the vulnerability does not require authentication, the low EPSS suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers could target the /rpc endpoint remotely via an unauthenticated WebSocket connection to trigger a server crash.

Generated by OpenCVE AI on August 1, 2026 at 07:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 3.1.0 or later; this version resolves the underlying CWE-248 issue in the RPC use handler.
  • If an upgrade is not feasible, block or restrict access to the /rpc endpoint or WebSocket connections at the firewall or load balancer.
  • Continuously monitor server logs for repeated 'panic' errors or abnormal RPC traffic and investigate any retry requests that could indicate an attacker.

Generated by OpenCVE AI on August 1, 2026 at 07:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.
Title SurrealDB before 3.1.0 Denial of Service via malformed RPC use
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:05:41.626Z

Reserved: 2026-07-18T12:26:19.866Z

Link: CVE-2026-63747

cve-icon Vulnrichment

Updated: 2026-07-23T19:19:49.746Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:30:13Z

Weaknesses