CVE-2026-63760

HIGH

SurrealDB before 3.1.0 Denial of Service via JSON Parser

Title source: cna
STIX 2.1

Description

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-q729-696q-g9pq)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q729-696q-g9pq
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.1.0 Denial of Service via JSON Parser
https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-json-parser

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 28.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (2)
surrealdb/surrealdb < 3.1.0 (2 CPE variants)
surrealdb/surrealdb 3.1.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026