VYPR
Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 28, 2026

SurrealDB before 1.1.0 Uncontrolled Recursion Denial of Service

CVE-2024-58370

Description

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack overflow and crash the server.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.