← Späť na vyhľadávanie CVE

CVE-2026-63760

SurrealDB

Popis

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.

CVSS 7.5EPSS 0.359%Riziko 0.77
Zobraziť zdroj
Zverejnené
2026-07-20 12:19:46
Dotknuté verzie
<3.1.0
Typ
Kritický softvér
Posledná úprava
2026-07-22 15:08:06
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H