← Back to CVE search

CVE-2024-58370

SurrealDB

Description

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to cause stack overflow and crash the server.

CVSS 6.5EPSS 0.27499999999999997%Risk 0.67
View source
Published
2026-07-18 14:17:10
Affected versions
<1.1.0
Type
Critical software
Last modified
2026-07-22 19:16:53
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H