VYPR
Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 28, 2026

SurrealDB before 1.2.0 Denial of Service via Nonexistent Function

CVE-2024-58365

Description

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.