Description
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.
Published: 2026-07-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SurrealDB fails to enforce recursion depth limits in its type/kind parser when handling nested type annotations. When an authenticated user sends a query with deeply nested annotations, the parser consumes excessive memory, eventually crashing the server process. This results in a denial of service that disrupts availability for all users.

Affected Systems

The vulnerability affects all SurrealDB deployments using versions prior to 3.1.0. Authentication is required to submit queries; therefore, only users with legitimate access to the database can leverage the flaw. Administrators should verify the current version against the vendor’s release history.

Risk and Exploitability

The CVSS score is 7.1, indicating a medium‑to‑high severity. The EPSS score is < 1%, suggesting a very low probability of exploitation, and KEV is not listed. An attacker who has authenticated database access can trigger the denial of service by constructing a query with a deeply nested type annotation, thereby exhausting memory resources.

Generated by OpenCVE AI on July 30, 2026 at 19:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to SurrealDB 3.1.0 or later, which includes enforced recursion depth limits.
  • Restrict authenticated access to limit the number of queries that can contain complex type annotations, and consider implementing request size or processing time limits.
  • Implement a watchdog or automated restart strategy to recover from process crashes and monitor memory usage for anomalous spikes.

Generated by OpenCVE AI on July 30, 2026 at 19:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.
Title SurrealDB before 3.1.0 Denial of Service nested type annotations
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:05:50.034Z

Reserved: 2026-07-18T12:30:08.354Z

Link: CVE-2026-63759

cve-icon Vulnrichment

Updated: 2026-07-23T18:54:43.129Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:45:06Z

Weaknesses